7.7
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Description
The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated users, such as subscriber to perform SQLI attacks
Basic Information
ID
CVE-2025-13000
Source
WPScan
Published
Dec 2, 2025 at 06:00
Modified
Dec 2, 2025 at 13:34
Affected Product
Vendor
Unknown
Product
db-access
Affected Versions
Unknown db-access 0