VYPR
High severity8.5NVD Advisory· Published Aug 20, 2025· Updated Apr 23, 2026

CVE-2025-49891

CVE-2025-49891

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in uxper Uxper Booking uxper-booking allows Blind SQL Injection.This issue affects Uxper Booking: from n/a through <= 1.3.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Blind SQL injection in Uxper Booking WordPress plugin (<=1.3.3) allows unauthenticated attackers to extract database contents.

Vulnerability

Overview

The Uxper Booking plugin for WordPress (versions up to and including 1.3.3) contains a blind SQL injection vulnerability due to improper neutralization of special elements used in an SQL command [1]. This flaw allows an attacker to inject arbitrary SQL queries into the database through the plugin's input fields, without needing prior authentication.

Exploitation

The vulnerability is remotely exploitable and does not require any special privileges. Attackers can send crafted HTTP requests to the vulnerable endpoint, injecting SQL commands that are executed blindly. The Patchstack advisory notes that this type of vulnerability is highly dangerous and expected to be used in mass-exploit campaigns targeting thousands of websites regardless of size or popularity [1].

Impact

Successful exploitation enables an attacker to interact directly with the WordPress database. This can lead to the extraction of sensitive information such as user credentials, personal data, and other stored content. The CVSS v3 score of 8.5 (High) reflects the potential for significant data breach and system compromise [1].

Mitigation

Users are strongly advised to update the Uxper Booking plugin to the latest patched version immediately. If an update is not available, contact the plugin vendor or a web developer for assistance. Given the active threat landscape, applying the fix without delay is critical [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.