VYPR
High severity7.6NVD Advisory· Published May 23, 2025· Updated Apr 23, 2026

CVE-2025-47671

CVE-2025-47671

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LETSCMS MLM Software Binary MLM Plan binary-mlm-plan allows SQL Injection.This issue affects Binary MLM Plan: from n/a through <= 3.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unsanitized SQL inputs in the Binary MLM Plan WordPress plugin <=3.0 let unauthenticated attackers execute arbitrary SQL commands.

The Binary MLM Plan plugin for WordPress, versions 3.0 and earlier, contains a SQL injection vulnerability due to improper neutralization of special elements used in an SQL command [1]. This type of flaw occurs when user-supplied data is directly concatenated into SQL queries without proper sanitization or parameterization, allowing an attacker to manipulate the intended query logic.

Exploitation requires no authentication; the attacker only needs network access to the WordPress site. By crafting malicious input in a parameter that feeds into a SQL query, the attacker can inject arbitrary SQL commands [1]. The vulnerability is considered highly dangerous and is expected to be used in mass-exploit campaigns, targeting thousands of sites automatically, regardless of their size or popularity [1].

The impact is severe: a successful attack could allow the malicious actor to directly interact with the database, enabling theft of sensitive information such as user credentials, personal data, and site content [1]. Attackers might also be able to modify or delete data, compromise the entire WordPress installation, or gain further access to the server.

As of the advisory, the vulnerability has been patched in version 5.0 of the plugin. Users are strongly urged to update immediately. For those unable to update, applying a virtual patch or mitigation rule, such as the one provided by Patchstack, can block attacks until the update is performed [1]. No other workarounds have been documented.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.