VYPR
High severity7.6NVD Advisory· Published Jul 16, 2025· Updated Apr 23, 2026

CVE-2025-49034

CVE-2025-49034

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Funnel Builder by FunnelKit funnel-builder allows SQL Injection.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.10.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SQL injection vulnerability in Funnel Builder by FunnelKit plugin for WordPress (≤3.10.2) allows unauthenticated attackers to execute arbitrary SQL commands.

Vulnerability

Overview

The Funnel Builder by FunnelKit plugin for WordPress, versions 3.10.2 and earlier, contains an SQL injection vulnerability due to improper neutralization of special elements used in SQL commands [1]. This flaw allows an attacker to inject malicious SQL queries through user-supplied input that is not properly sanitized before being used in database operations.

Exploitation

The vulnerability can be exploited without authentication, making it accessible to any remote attacker. By sending specially crafted requests, an attacker can manipulate SQL queries executed by the plugin. According to the advisory, such vulnerabilities are frequently used in mass-exploit campaigns targeting thousands of websites regardless of their size or popularity [1].

Impact

Successful exploitation enables an attacker to directly interact with the underlying database. This could lead to unauthorized access to sensitive information, including user data, credentials, and other stored content. The CVSS v3 base score of 7.6 (High) reflects the potential for significant data compromise [1].

Mitigation

The vulnerability has been addressed in version 3.11.0 of the plugin. Users are strongly advised to update immediately. If updating is not possible, consulting with a hosting provider or web developer is recommended. Patchstack users can enable auto-updates for vulnerable plugins to ensure timely patching [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.