CVE-2025-22527
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yamna Khawaja Mailing Group Listserv wp-mailing-group allows SQL Injection.This issue affects Mailing Group Listserv: from n/a through <= 2.0.9.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
SQL injection in WordPress Mailing Group Listserv plugin up to 2.0.9 allows unauthenticated attackers to execute arbitrary SQL commands, risking data theft.
Vulnerability
Overview
The Mailing Group Listserv plugin for WordPress (wp-mailing-group) contains a SQL injection vulnerability due to improper neutralization of special elements used in SQL commands. Versions from n/a through 2.0.9 are affected. This flaw allows an attacker to inject malicious SQL queries into the application's database interactions [1].
Exploitation
Attackers can exploit this vulnerability without authentication by sending specially crafted HTTP requests to any WordPress site running the vulnerable plugin. The reference notes that such vulnerabilities are frequently used in mass-exploit campaigns, targeting thousands of websites regardless of size or popularity [1]. No special network position is required; the attack can be carried out remotely.
Impact
Successful exploitation enables an attacker to directly interact with the database, potentially extracting sensitive information such as user credentials, personal data, or other stored content. This could lead to further compromise of the site and its users [1].
Mitigation
The vendor has released version 3.0.0 which resolves the vulnerability. Users are strongly advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. If updating is not possible, consulting a hosting provider or web developer is recommended [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=2.0.9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.