VYPR
High severity7.6NVD Advisory· Published Mar 3, 2025· Updated Apr 23, 2026

CVE-2025-25112

CVE-2025-25112

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kareemsultan Social Links social-links allows Command Line Execution through SQL Injection.This issue affects Social Links: from n/a through <= 1.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The Social Links WordPress plugin ≤1.2 is vulnerable to SQL injection that can lead to command line execution, allowing unauthenticated attackers to execute arbitrary commands on the database.

The Social Links plugin for WordPress (version 1.2 and earlier) contains an SQL injection vulnerability due to improper neutralization of special elements used in SQL commands [1]. This flaw allows an attacker to inject arbitrary SQL statements into the database query, potentially leading to command line execution on the underlying database server.

Exploitation does not require authentication; an attacker can send crafted HTTP requests to the plugin's endpoints to trigger the injection. No special privileges or network position beyond standard web access is needed, making the attack surface broad and accessible to remote unauthenticated users.

Successful exploitation can result in command line execution, enabling the attacker to extract sensitive data, modify database contents, or execute system commands. The advisory notes that vulnerabilities of this type are frequently used in mass-exploit campaigns targeting thousands of websites [1].

Users are strongly advised to update the plugin to a patched version as soon as possible. If an update is not available, contacting the hosting provider or a web developer for mitigation assistance is recommended [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.