Unrated severityNVD Advisory· Published Jun 4, 2025· Updated Jun 4, 2025
File Provider <= 1.2.3 - Unauthenticated SQLi
CVE-2025-4578
Description
The File Provider WordPress plugin through 1.2.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
Affected products
2- WordPress/File Providerdescription
- Range: <=1.2.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/3aa76b96-40b7-4bde-a39c-c1aa6f8278fc/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.