<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Time-based SQL Injection</title>
  <link>https://cvedaily.com/pages/tags/time-sql.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/time-sql.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Time-based SQL Injection</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:44 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-9010 – The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9010</guid>
    <pubDate>Wed, 20 May 2026 04:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9010</strong></p>
  <p>The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL queries. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing quer…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4798 – The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4798</guid>
    <pubDate>Wed, 13 May 2026 13:01:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4798</strong></p>
  <p>The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4062 – The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4062</guid>
    <pubDate>Sat, 02 May 2026 12:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4062</strong></p>
  <p>The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'object_ids' and 'exclude_object_ids' parameters in all versions up to, and including, 1.13.18. This is due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. The `esc_sql()` function is applied but is ineffective because the values are placed i…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4061 – The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4061</guid>
    <pubDate>Sat, 02 May 2026 12:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4061</strong></p>
  <p>The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all versions up to, and including, 1.13.18. This is due to the `SearchResults` hook explicitly calling `stripslashes_deep($_POST)` which removes WordPress magic quotes protection, followed by the unsanitized `map_post_type` value being concatenated into an `IN(...)` clause without `e…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4060 – The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4060</guid>
    <pubDate>Sat, 02 May 2026 12:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4060</strong></p>
  <p>The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.18. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The `esc_sql()` function is applied but is ineffective in the `ORDER BY` context because the value is not enclosed in q…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3396 – WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3396</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3396</guid>
    <pubDate>Wed, 08 Apr 2026 12:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3396</strong></p>
  <p>WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the 'post-author' parameter in all versions up to, and including, 4.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing quer…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3396">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39341 – ChurchCRM is an open-source church management system. Prior to 7.1.0, the applic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39341</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39341</guid>
    <pubDate>Tue, 07 Apr 2026 18:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39341</strong></p>
  <p>ChurchCRM is an open-source church management system. Prior to 7.1.0, the application is vulnerable to time-based SQL injection due to an improper input validation. Endpoint Reports/ConfirmReportEmail.php?familyId= is not correctly sanitising user input, specifically, the sanitised input is not used to create the SQL query. This vulnerability is fixed in 7.1.0.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39341">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-36058 – The Send Basket functionality in Koha Library before 23.05.10 is susceptible to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36058</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-36058</strong></p>
  <p>The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parameter bib_list in /cgi-bin/koha/opac-sendbasket.pl, allowing library users to read arbitrary data from the database.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25664 – SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25664</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25664</guid>
    <pubDate>Sun, 05 Apr 2026 21:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25664</strong></p>
  <p>SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView action that allows authenticated attackers to manipulate database queries. Attackers can append SQL code to the record parameter in GET requests to the index.php endpoint to extract sensitive database information through time-based blind SQL injection techniques.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25664">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3079 – The LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3079</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3079</guid>
    <pubDate>Tue, 24 Mar 2026 02:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3079</strong></p>
  <p>The LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Injection via the 'filters[orderby_order]' parameter in the 'learndash_propanel_template' AJAX action in all versions up to, and including, 5.0.3. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated atta…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3079">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2580 – The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp;...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2580</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2580</guid>
    <pubDate>Mon, 23 Mar 2026 00:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2580</strong></p>
  <p>The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2580">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2503 – The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2503</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2503</guid>
    <pubDate>Sat, 21 Mar 2026 04:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2503</strong></p>
  <p>The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection via the 'meta_query[compare]' parameter in the 'tcg_select2_search_post' AJAX action in all versions up to, and including, 2.3.6. This is due to the user-supplied compare value being placed as an SQL operator in the query without validation against an allowlist of comparison operators. The value is passed through esc_s…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2503">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1800 – The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to time-base...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1800</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1800</guid>
    <pubDate>Sat, 21 Mar 2026 04:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1800</strong></p>
  <p>The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘fmcfIdSelectedFnt’ parameter in all versions up to, and including, 1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already e…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1800">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25535 – Netartmedia PHP Dating Site contains a SQL injection vulnerability that allows u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25535</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25535</guid>
    <pubDate>Thu, 12 Mar 2026 16:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25535</strong></p>
  <p>Netartmedia PHP Dating Site contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with time-based SQL injection payloads in the Email field to extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25535">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25519 – Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25519</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25519</guid>
    <pubDate>Thu, 12 Mar 2026 16:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25519</strong></p>
  <p>Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting malicious SQL code through the option parameter. Attackers can send POST requests to uyelik.php with crafted payloads in the option parameter to execute time-based SQL injection attacks and extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25519">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25500 – Simple Job Script contains an SQL injection vulnerability that allows unauthenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25500</guid>
    <pubDate>Wed, 04 Mar 2026 18:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25500</strong></p>
  <p>Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the employerid parameter. Attackers can send POST requests to the register-recruiters endpoint with time-based SQL injection payloads to extract sensitive data or modify database contents.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-50192 – Chamilo is a learning management system. Prior to version 1.11.30, there is a ti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50192</guid>
    <pubDate>Mon, 02 Mar 2026 15:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-50192</strong></p>
  <p>Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main/webservices/registration.soap.php. This issue has been patched in version 1.11.30.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25490 – Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25490</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25490</guid>
    <pubDate>Fri, 27 Feb 2026 18:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25490</strong></p>
  <p>Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'id' parameter. Attackers can send GET requests to the admin/edit.php endpoint with time-based SQL injection payloads to extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25490">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25460 – Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25460</guid>
    <pubDate>Sun, 22 Feb 2026 15:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25460</strong></p>
  <p>Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' GET parameter. Attackers can send requests to the arama endpoint with malicious 'q' values using time-based SQL injection techniques to extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-25456 – Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25456</guid>
    <pubDate>Sun, 22 Feb 2026 15:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-25456</strong></p>
  <p>Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'ara' GET parameter. Attackers can send requests to with time-based SQL injection payloads to extract sensitive database information or cause denial of service.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25439 – NoviSmart CMS contains an SQL injection vulnerability that allows remote attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25439</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25439</guid>
    <pubDate>Sun, 22 Feb 2026 14:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25439</strong></p>
  <p>NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the Referer HTTP header field. Attackers can craft requests with time-based SQL injection payloads in the Referer header to extract sensitive database information or cause denial of service.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25439">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2232 – The Product Table and List Builder for WooCommerce Lite plugin for WordPress is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2232</guid>
    <pubDate>Thu, 19 Feb 2026 17:24:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2232</strong></p>
  <p>The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 4.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries i…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1581 – The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1581</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1581</guid>
    <pubDate>Thu, 19 Feb 2026 17:24:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1581</strong></p>
  <p>The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can b…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1581">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2576 – The Business Directory Plugin – Easy Listing Directories for WordPress plugin fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2576</guid>
    <pubDate>Wed, 18 Feb 2026 05:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2576</strong></p>
  <p>The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the 'payment' parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append addition…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13431 – The SlimStat Analytics plugin for WordPress is vulnerable to time-based SQL Inje...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13431</guid>
    <pubDate>Wed, 11 Feb 2026 02:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13431</strong></p>
  <p>The SlimStat Analytics plugin for WordPress is vulnerable to time-based SQL Injection via the ‘args’ parameter in all versions up to, and including, 5.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL quer…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-10258 – Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10258</guid>
    <pubDate>Thu, 05 Feb 2026 08:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-10258</strong></p>
  <p>Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may result in leaking of sensitive information.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1370 – The SIBS woocommerce payment gateway plugin for WordPress is vulnerable to time-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1370</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1370</guid>
    <pubDate>Wed, 04 Feb 2026 09:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1370</strong></p>
  <p>The SIBS woocommerce payment gateway plugin for WordPress is vulnerable to time-based SQL Injection via the ‘referencedId’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Administrator-level access and above, to a…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1370">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0816 – The All push notification for WP plugin for WordPress is vulnerable to time-base...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0816</guid>
    <pubDate>Wed, 04 Feb 2026 09:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0816</strong></p>
  <p>The All push notification for WP plugin for WordPress is vulnerable to time-based SQL Injection via the 'delete_id' parameter in all versions up to, and including, 1.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append ad…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37005 – TimeClock Software 1.01 contains an authenticated time-based SQL injection vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37005</guid>
    <pubDate>Thu, 29 Jan 2026 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37005</strong></p>
  <p>TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumerate valid usernames by manipulating the 'notes' parameter. Attackers can inject conditional time delays in the add_entry.php endpoint to determine user existence by measuring response time differences.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0702 – The VidShop – Shoppable Videos for WooCommerce plugin for WordPress is vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0702</guid>
    <pubDate>Wed, 28 Jan 2026 09:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0702</strong></p>
  <p>The VidShop – Shoppable Videos for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'fields' parameter in all versions up to, and including, 1.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alrea…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0678 – The Flat Shipping Rate by City for WooCommerce plugin for WordPress is vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0678</guid>
    <pubDate>Wed, 14 Jan 2026 06:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0678</strong></p>
  <p>The Flat Shipping Rate by City for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'cities' parameter in all versions up to, and including, 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-9318 – The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9318</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9318</guid>
    <pubDate>Tue, 06 Jan 2026 10:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-9318</strong></p>
  <p>The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injection via the ‘is_linking’ parameter in all versions up to, and including, 10.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Subscriber-level a…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9318">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14153 – The Page Expire Popup/Redirection for WordPress plugin for WordPress is vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14153</guid>
    <pubDate>Tue, 06 Jan 2026 04:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14153</strong></p>
  <p>The Page Expire Popup/Redirection for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' shortcode attribute in all versions up to, and including, 1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Author-level access and above, to…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14068 – The WPNakama plugin for WordPress is vulnerable to time-based SQL Injection via ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14068</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14068</guid>
    <pubDate>Fri, 12 Dec 2025 07:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14068</strong></p>
  <p>The WPNakama plugin for WordPress is vulnerable to time-based SQL Injection via the 'order_by' parameter in all versions up to, and including, 0.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14068">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-10163 – The List category posts plugin for WordPress is vulnerable to time-based SQL Inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10163</guid>
    <pubDate>Thu, 11 Dec 2025 04:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-10163</strong></p>
  <p>The List category posts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘starting_with’ parameter of the catlist shortcode in all versions up to, and including, 0.91.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Contributor-level access and…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13359 – The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for W...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13359</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13359</guid>
    <pubDate>Wed, 03 Dec 2025 14:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13359</strong></p>
  <p>The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL Injection via the "getTermsForAjax"  function in all versions up to, and including, 3.40.1. This is due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, wit…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13359">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13385 – The Bookme – Free Online Appointment Booking and Scheduling Plugin for WordPress...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13385</guid>
    <pubDate>Tue, 25 Nov 2025 08:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13385</strong></p>
  <p>The Bookme – Free Online Appointment Booking and Scheduling Plugin for WordPress is vulnerable to time-based SQL Injection via the `filter[status]` parameter in all versions up to, and including, 4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with admin-level access a…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13370 – The ProjectList plugin for WordPress is vulnerable to time-based SQL Injection v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13370</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13370</guid>
    <pubDate>Tue, 25 Nov 2025 08:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13370</strong></p>
  <p>The ProjectList plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 0.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Editor-level access and above, to append additional SQL queries into alrea…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13370">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-10144 – The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-ba...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10144</guid>
    <pubDate>Mon, 24 Nov 2025 23:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-10144</strong></p>
  <p>The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attribute of the `products` shortcode in all versions up to, and including, 3.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Contributor-level acce…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7402 – The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for Word...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7402</guid>
    <pubDate>Mon, 24 Nov 2025 05:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7402</strong></p>
  <p>The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘site_id’ parameter in all versions up to, and including, 4.95 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65024 – i-Educar is free, fully online school management software. In versions 2.10.0 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65024</guid>
    <pubDate>Wed, 19 Nov 2025 16:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65024</strong></p>
  <p>i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/agenda_admin_cad.php script. An attacker with access to an authenticated session can execute arbitrary SQL commands against the application's database. This vulnerability is caused by the improper handling of the cod_agenda…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65023 – i-Educar is free, fully online school management software. In versions 2.10.0 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65023</guid>
    <pubDate>Wed, 19 Nov 2025 16:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65023</strong></p>
  <p>i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/funcionario_vinculo_cad.php script. An attacker with access to an authenticated session can execute arbitrary SQL commands against the application's database. This vulnerability is caused by the improper handling of the cod…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65022 – i-Educar is free, fully online school management software. In versions 2.10.0 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65022</guid>
    <pubDate>Wed, 19 Nov 2025 16:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65022</strong></p>
  <p>i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/agenda.php script. An attacker with access to an authenticated session can execute arbitrary SQL commands against the application's database. This vulnerability is caused by the improper handling of the cod_agenda request p…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-8994 – The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Man...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8994</guid>
    <pubDate>Sat, 15 Nov 2025 06:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-8994</strong></p>
  <p>The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘completed_at_operator’ parameter in all versions up to, and including, 2.6.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4203 – The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4203</guid>
    <pubDate>Sat, 25 Oct 2025 07:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4203</strong></p>
  <p>The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() function in all versions up to, and including, 2.4.8 due to missing integer validation on the 'offset' and 'row_count' parameters. The function blindly interpolates 'row_count' into a 'LIMIT offset,row_count' clause using esc_sql() rather than enforcing numeric values. MySQL 5.x’s…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-9947 – The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9947</guid>
    <pubDate>Sat, 11 Oct 2025 10:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-9947</strong></p>
  <p>The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘path’ parameter in all versions up to, and including, 3.12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL quer…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9807 – The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9807</guid>
    <pubDate>Fri, 12 Sep 2025 02:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9807</strong></p>
  <p>The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all versions up to, and including, 6.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that c…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-9451 – The Smartcat Translator for WPML plugin for WordPress is vulnerable to time-base...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9451</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9451</guid>
    <pubDate>Thu, 11 Sep 2025 08:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-9451</strong></p>
  <p>The Smartcat Translator for WPML plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 3.1.72 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Author-level access and above, to append additiona…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9451">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-9776 – The CatFolders – Tame Your WordPress Media Library by Category plugin for WordPr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9776</guid>
    <pubDate>Thu, 11 Sep 2025 05:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-9776</strong></p>
  <p>The CatFolders – Tame Your WordPress Media Library by Category plugin for WordPress is vulnerable to time-based SQL Injection via the CSV Import contents in all versions up to, and including, 2.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Author-level access a…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-9463 – The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9463</guid>
    <pubDate>Wed, 10 Sep 2025 07:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-9463</strong></p>
  <p>The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 1.117.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated at…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-6189 – The Duplicate Page and Post plugin for WordPress is vulnerable to time-based SQL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6189</guid>
    <pubDate>Wed, 10 Sep 2025 07:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-6189</strong></p>
  <p>The Duplicate Page and Post plugin for WordPress is vulnerable to time-based SQL Injection via the ‘meta_key’ parameter in all versions up to, and including, 2.9.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Contributor-level access and above, to append additiona…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-10003 – The UsersWP – Front-end login form, User Registration, User Profile &amp; Members Di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10003</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10003</guid>
    <pubDate>Sat, 06 Sep 2025 03:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-10003</strong></p>
  <p>The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘upload_file_remove’ function and 'htmlvar' parameter in all versions up to, and including, 1.2.44 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10003">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-9441 – The iATS Online Forms plugin for WordPress is vulnerable to time-based SQL Injec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9441</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9441</guid>
    <pubDate>Fri, 29 Aug 2025 05:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-9441</strong></p>
  <p>The iATS Online Forms plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order' parameter in all versions up to, and including, 1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queri…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9441">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-8977 – The Simple Download Monitor plugin for WordPress is vulnerable to time-based SQL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8977</guid>
    <pubDate>Thu, 28 Aug 2025 05:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-8977</strong></p>
  <p>The Simple Download Monitor plugin for WordPress is vulnerable to time-based SQL Injection via the order parameter in all versions up to, and including, 3.9.33 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Contributor-level access and above, and permissions granted…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9172 – The Vibes plugin for WordPress is vulnerable to time-based SQL Injection via the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9172</guid>
    <pubDate>Tue, 26 Aug 2025 04:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9172</strong></p>
  <p>The Vibes plugin for WordPress is vulnerable to time-based SQL Injection via the ‘resource’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be us…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7670 – The JS Archive List plugin for WordPress is vulnerable to time-based SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7670</guid>
    <pubDate>Tue, 19 Aug 2025 08:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7670</strong></p>
  <p>The JS Archive List plugin for WordPress is vulnerable to time-based SQL Injection via the build_sql_where() function in all versions up to, and including, 6.1.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing querie…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6184 – The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6184</guid>
    <pubDate>Wed, 13 Aug 2025 07:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6184</strong></p>
  <p>The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter used in the get_submitted_assignments() function in all versions up to, and including, 3.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authentica…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7036 – The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7036</guid>
    <pubDate>Wed, 06 Aug 2025 02:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7036</strong></p>
  <p>The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all versions up to, and including, 1.5.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that c…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-6348 – The Smart Slider 3 plugin for WordPress is vulnerable to time-based SQL Injectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6348</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6348</guid>
    <pubDate>Wed, 30 Jul 2025 09:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-6348</strong></p>
  <p>The Smart Slider 3 plugin for WordPress is vulnerable to time-based SQL Injection via the ‘sliderid’ parameter in all versions up to, and including, 3.5.1.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQ…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6348">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13507 – The GeoDirectory – WP Business Directory Plugin and Classified Listings Director...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13507</guid>
    <pubDate>Sat, 26 Jul 2025 04:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13507</strong></p>
  <p>The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to time-based SQL Injection via the dist parameter in all versions up to, and including, 2.8.97 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-7638 – The Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder plugin f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7638</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7638</guid>
    <pubDate>Fri, 18 Jul 2025 05:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-7638</strong></p>
  <p>The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the `order_by` parameter in all versions up to, and including, 1.45.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Administra…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7638">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6970 – The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6970</guid>
    <pubDate>Wed, 09 Jul 2025 23:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6970</strong></p>
  <p>The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL que…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5339 – The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for Word...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5339</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5339</guid>
    <pubDate>Wed, 02 Jul 2025 04:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5339</strong></p>
  <p>The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘bsa_pro_id’ parameter in all versions up to, and including, 4.89 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5339">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5590 – The Owl carousel responsive plugin for WordPress is vulnerable to time-based SQL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5590</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5590</guid>
    <pubDate>Thu, 26 Jun 2025 02:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5590</strong></p>
  <p>The Owl carousel responsive plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL qu…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5590">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5487 – The AutomatorWP – Automator plugin for no-code automations, webhooks &amp; custom in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5487</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5487</guid>
    <pubDate>Sat, 14 Jun 2025 07:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5487</strong></p>
  <p>The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the field_conditions parameter in all versions up to, and including, 5.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for aut…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5487">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-4964 – The WP Online Users Stats plugin for WordPress is vulnerable to time-based SQL I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4964</guid>
    <pubDate>Fri, 06 Jun 2025 07:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-4964</strong></p>
  <p>The WP Online Users Stats plugin for WordPress is vulnerable to time-based SQL Injection via the ‘table_name’ parameter in all versions up to, and including, 1.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Editor-level access and above, to append additional SQL…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-57459 – A time-based SQL injection vulnerability exists in mydetailsstudent.php in the C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-57459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-57459</guid>
    <pubDate>Mon, 02 Jun 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-57459</strong></p>
  <p>A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds parameter does not properly validate user input, allowing an attacker to inject arbitrary SQL commands.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-57459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3107 – The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3107</guid>
    <pubDate>Tue, 13 May 2025 07:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3107</strong></p>
  <p>The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby' parameter in all versions up to, and including, 4.9.9.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queri…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4396 – The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-base...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4396</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4396</guid>
    <pubDate>Tue, 13 May 2025 04:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4396</strong></p>
  <p>The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags query parameters in all versions up to, and including, 4.24.4 (Free) and <= 2.27.5 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append ad…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4396">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2890 – The tagDiv Opt-In Builder plugin for WordPress is vulnerable to time-based SQL I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2890</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2890</guid>
    <pubDate>Wed, 30 Apr 2025 09:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2890</strong></p>
  <p>The tagDiv Opt-In Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘subscriptionCouponId’ parameter in all versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Subscriber-level access and above, to append ad…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2890">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2128 – The Cost Calculator Builder plugin for WordPress is vulnerable to time-based SQL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2128</guid>
    <pubDate>Fri, 11 Apr 2025 10:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2128</strong></p>
  <p>The Cost Calculator Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_ids’ parameter in all versions up to, and including, 3.2.67 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Subscriber-level access and above, to append addition…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13909 – The Accredible Certificates &amp; Open Badges plugin for WordPress is vulnerable to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13909</guid>
    <pubDate>Thu, 10 Apr 2025 07:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13909</strong></p>
  <p>The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Administrator-level access and above, to a…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2317 – The Product Filter by WBW plugin for WordPress is vulnerable to time-based SQL I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2317</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2317</guid>
    <pubDate>Fri, 04 Apr 2025 06:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2317</strong></p>
  <p>The Product Filter by WBW plugin for WordPress is vulnerable to time-based SQL Injection via the filtersDataBackend parameter in all versions up to, and including, 2.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existin…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2317">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2478 – The Code Clone plugin for WordPress is vulnerable to time-based SQL Injection vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2478</guid>
    <pubDate>Sat, 22 Mar 2025 07:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2478</strong></p>
  <p>The Code Clone plugin for WordPress is vulnerable to time-based SQL Injection via the ‘snippetId’ parameter in all versions up to, and including, 0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0723 – The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0723</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0723</guid>
    <pubDate>Sat, 22 Mar 2025 05:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0723</strong></p>
  <p>The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL Injections via the rid and search parameters in all versions up to, and including, 5.9.4.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Subscribe…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0723">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2511 – The AHAthat Plugin plugin for WordPress is vulnerable to time-based SQL Injectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2511</guid>
    <pubDate>Wed, 19 Mar 2025 12:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2511</strong></p>
  <p>The AHAthat Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries i…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2221 – The WPCOM Member plugin for WordPress is vulnerable to time-based SQL Injection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2221</guid>
    <pubDate>Fri, 14 Mar 2025 07:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2221</strong></p>
  <p>The WPCOM Member plugin for WordPress is vulnerable to time-based SQL Injection via the ‘user_phone’ parameter in all versions up to, and including, 1.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-1702 – The Ultimate Member – User Profile, Registration, Login, Member Directory, Conte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1702</guid>
    <pubDate>Wed, 05 Mar 2025 12:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1702</strong></p>
  <p>The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 2.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13846 – The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-base...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13846</guid>
    <pubDate>Fri, 21 Feb 2025 12:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13846</strong></p>
  <p>The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parameter in all versions up to, and including, 3.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Administrator-level access and above, to append addit…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11260 – The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11260</guid>
    <pubDate>Fri, 21 Feb 2025 06:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11260</strong></p>
  <p>The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0866 – The Legoeso PDF Manager plugin for WordPress is vulnerable to time-based SQL Inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0866</guid>
    <pubDate>Thu, 20 Feb 2025 10:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0866</strong></p>
  <p>The Legoeso PDF Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘checkedVals’ parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Author-level access and above, to append additional SQL…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-55460 – A time-based SQL injection vulnerability in the login page of BoardRoom Limited ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55460</guid>
    <pubDate>Tue, 18 Feb 2025 17:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-55460</strong></p>
  <p>A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election System Version v2.0 allows attackers to execute arbitrary code via a crafted input.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13369 – The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13369</guid>
    <pubDate>Tue, 18 Feb 2025 10:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13369</strong></p>
  <p>The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all versions up to, and including, 5.3.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Subscriber-level access and above, t…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13500 – The WP Project Manager – Task, team, and project management plugin featuring kan...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13500</guid>
    <pubDate>Sat, 15 Feb 2025 12:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13500</strong></p>
  <p>The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.6.17 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authen…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0821 – Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0821</guid>
    <pubDate>Fri, 14 Feb 2025 11:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0821</strong></p>
  <p>Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into alrea…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13496 – The GamiPress – Gamification plugin to reward points, achievements, badges &amp; ran...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13496</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13496</guid>
    <pubDate>Wed, 22 Jan 2025 11:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13496</strong></p>
  <p>The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated at…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13496">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13184 – The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13184</guid>
    <pubDate>Sat, 18 Jan 2025 09:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13184</strong></p>
  <p>The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the Login Attempts module in all versions up to, and including, 3.0.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries int…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0308 – The Ultimate Member – User Profile, Registration, Login, Member Directory, Conte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0308</guid>
    <pubDate>Sat, 18 Jan 2025 06:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0308</strong></p>
  <p>The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the search parameter in all versions up to, and including, 2.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for un…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11939 – The Cost Calculator Builder PRO plugin for WordPress is vulnerable to blind time...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11939</guid>
    <pubDate>Wed, 08 Jan 2025 09:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11939</strong></p>
  <p>The Cost Calculator Builder PRO plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘data’ parameter in all versions up to, and including, 3.2.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existin…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-12635 – The WP Docs plugin for WordPress is vulnerable to time-based SQL Injection via t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-12635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-12635</guid>
    <pubDate>Sat, 21 Dec 2024 07:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-12635</strong></p>
  <p>The WP Docs plugin for WordPress is vulnerable to time-based SQL Injection via the 'dir_id' parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-12635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11912 – The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind ti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11912</guid>
    <pubDate>Wed, 18 Dec 2024 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11912</strong></p>
  <p>The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind time-based SQL Injection via the ‘order_id’ parameter in all versions up to, and including, 3.1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already e…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-10247 – The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10247</guid>
    <pubDate>Fri, 06 Dec 2024 04:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-10247</strong></p>
  <p>The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the orderby parameter in all versions up to, and including, 2.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Administrator-level access a…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-11732 – The BP Profile Shortcodes Extra plugin for WordPress is vulnerable to time-based...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11732</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11732</guid>
    <pubDate>Tue, 03 Dec 2024 08:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-11732</strong></p>
  <p>The BP Profile Shortcodes Extra plugin for WordPress is vulnerable to time-based SQL Injection via the ‘tab’ parameter in all versions up to, and including, 2.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11732">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-11009 – The Internal Linking for SEO traffic &amp; Ranking – Auto internal links (100% autom...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11009</guid>
    <pubDate>Wed, 27 Nov 2024 12:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-11009</strong></p>
  <p>The Internal Linking for SEO traffic & Ranking – Auto internal links (100% automatic) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parameter in all versions up to, and including, 1.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, wit…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-9887 – The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9887</guid>
    <pubDate>Sat, 16 Nov 2024 10:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-9887</strong></p>
  <p>The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.15.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Administrator-level access and above,…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-10645 – The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10645</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10645</guid>
    <pubDate>Sat, 16 Nov 2024 09:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-10645</strong></p>
  <p>The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘br’ parameter in all versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10645">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-9874 – The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9874</guid>
    <pubDate>Sat, 09 Nov 2024 07:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-9874</strong></p>
  <p>The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 5.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Administrator-level acce…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-10687 – The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Galler...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10687</guid>
    <pubDate>Tue, 05 Nov 2024 10:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-10687</strong></p>
  <p>The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to time-based SQL Injection via the $collectedIds parameter in all versions up to, and including, 24.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8757 – The WP Post Author – Boost Your Blog&amp;#039;s Engagement with Author Box, Social L...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8757</guid>
    <pubDate>Sat, 12 Oct 2024 10:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8757</strong></p>
  <p>The WP Post Author – Boost Your Blog&#039;s Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the linked_user_id parameter in all versions up to, and including, 3.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient p…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-9201 – The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9201</guid>
    <pubDate>Thu, 10 Oct 2024 11:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-9201</strong></p>
  <p>The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQL injection through the use of the ‘id_order’ parameter of the ‘/modules/seur/ajax/saveCodFee.php’ endpoint.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9201">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
