Description
The TARIFFUXX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4. This is due to insufficient neutralization of user-supplied input used directly in SQL queries. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject additional SQL into queries and extract sensitive information from the database via a crafted id attribute in the 'tariffuxx_configurator' shortcode.
Published: 2025-10-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Update Plugin
AI Analysis

Impact

The TARIFFUXX WordPress plugin is vulnerable to SQL Injection in versions 1.4 and earlier due to insufficient neutralization of user–supplied input. The flaw allows an authenticated user with Contributor-level or higher access to inject malicious SQL via the id attribute of the tariffuxx_configurator shortcode, potentially enabling unauthorized extraction of data from the database and compromising confidentiality.

Affected Systems

The vulnerability affects the TARIFFUXX plugin for WordPress. All installed versions up to and including 1.4 are susceptible; no other WordPress core components are impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity. The EPSS score of less than 1% suggests a very low exploitation probability at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires authenticated access, so an attacker must possess Contributor or higher credentials, typically by inserting a crafted id value into the shortcode within the WordPress administration interface. Once authenticated, the attacker could extract sensitive database content.

Generated by OpenCVE AI on April 21, 2026 at 02:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the TARIFFUXX plugin to the latest available version, which includes the SQL injection fix.
  • If an upgrade cannot be performed immediately, remove the tariffuxx_configurator shortcode or strip the id attribute so that no user input reaches the database query.
  • Ensure that only trusted users have Contributor or higher roles and enforce strong passwords to reduce the chance that an attacker gains the necessary access.

Generated by OpenCVE AI on April 21, 2026 at 02:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
References

Mon, 20 Oct 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 15 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Oct 2025 08:45:00 +0000

Type Values Removed Values Added
Description The TARIFFUXX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4. This is due to insufficient neutralization of user-supplied input used directly in SQL queries. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject additional SQL into queries and extract sensitive information from the database via a crafted id attribute in the 'tariffuxx_configurator' shortcode.
Title TARIFFUXX <= 1.4 - Authenticated (Contributor+) SQL Injection via tariffuxx_configurator Shortcode
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:30:37.358Z

Reserved: 2025-09-18T12:26:16.591Z

Link: CVE-2025-10682

cve-icon Vulnrichment

Updated: 2025-10-15T13:15:32.451Z

cve-icon NVD

Status : Deferred

Published: 2025-10-15T09:15:41.327

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-10682

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T02:30:25Z

Weaknesses