Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 29 Dec 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Mon, 29 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 29 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 29 Dec 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Plugin Organizer WordPress plugin before 10.2.4 does not sanitize and escape a parameter before using it in a SQL statement, allowing subscribers to perform SQL injection attacks. | |
| Title | Plugin Organizer < 10.2.4 - Subscriber+ SQLi | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-12-29T20:15:42.608Z
Reserved: 2025-11-19T14:52:54.279Z
Link: CVE-2025-13417
Updated: 2025-12-29T16:15:18.424Z
Status : Deferred
Published: 2025-12-29T06:15:50.580
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-13417
No data.
OpenCVE Enrichment
Updated: 2025-12-29T22:33:02Z
No weakness.