VYPR
High severity7.6NVD Advisory· Published Jan 9, 2025· Updated Apr 29, 2026

CVE-2025-22527

CVE-2025-22527

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yamna Khawaja Mailing Group Listserv wp-mailing-group allows SQL Injection.This issue affects Mailing Group Listserv: from n/a through <= 2.0.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SQL injection in WordPress Mailing Group Listserv plugin up to 2.0.9 allows unauthenticated attackers to execute arbitrary SQL commands, risking data theft.

Vulnerability

Overview

The Mailing Group Listserv plugin for WordPress (wp-mailing-group) contains a SQL injection vulnerability due to improper neutralization of special elements used in SQL commands. Versions from n/a through 2.0.9 are affected. This flaw allows an attacker to inject malicious SQL queries into the application's database interactions [1].

Exploitation

Attackers can exploit this vulnerability without authentication by sending specially crafted HTTP requests to any WordPress site running the vulnerable plugin. The reference notes that such vulnerabilities are frequently used in mass-exploit campaigns, targeting thousands of websites regardless of size or popularity [1]. No special network position is required; the attack can be carried out remotely.

Impact

Successful exploitation enables an attacker to directly interact with the database, potentially extracting sensitive information such as user credentials, personal data, or other stored content. This could lead to further compromise of the site and its users [1].

Mitigation

The vendor has released version 3.0.0 which resolves the vulnerability. Users are strongly advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. If updating is not possible, consulting a hosting provider or web developer is recommended [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.