CVE-2025-39370
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cnilsson iCafe Library icafe-library allows SQL Injection.This issue affects iCafe Library: from n/a through <= 1.8.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The iCafe Library WordPress plugin <=1.8.3 is vulnerable to unauthenticated SQL injection, allowing attackers to steal database contents.
The iCafe Library plugin for WordPress (versions up to and including 1.8.3) contains an SQL injection vulnerability due to improper neutralization of special elements used in SQL commands [1]. This flaw allows an attacker to inject arbitrary SQL queries into the application's database layer, bypassing intended input validation.
Exploitation does not require authentication, making it accessible to any remote attacker. The vulnerability is actively targeted in mass-exploit campaigns, where attackers scan for vulnerable installations and inject malicious SQL payloads [1]. No special network position is needed; the attack can be carried out over HTTP requests to the WordPress site.
Successful exploitation enables an attacker to directly interact with the underlying database, potentially extracting sensitive information such as user credentials, personal data, or other stored content [1]. The CVSS v3 score of 7.6 reflects the high impact on confidentiality and the low complexity of the attack.
As a mitigation, users should immediately update the iCafe Library plugin to a version newer than 1.8.3, which contains a fix for this vulnerability [1]. If an update is not possible, contacting the hosting provider or a web developer for assistance is recommended.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<= 1.8.3+ 1 more
- (no CPE)range: <= 1.8.3
- (no CPE)range: <= 1.8.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.