Description
Insertion of Sensitive Information Into Sent Data vulnerability in Niket Joshi WPDB to Sql wpdb-to-sql allows Retrieve Embedded Sensitive Data.This issue affects WPDB to Sql: from n/a through <= 1.2.
Published: 2025-01-22
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Niket Joshi WPDB to Sql WordPress plugin allows the attacker to insert sensitive information into outgoing data streams, resulting in the exposure of confidential data stored within the database. According to the official description, a flaw in the plugin’s handling of query responses permits embedded sensitive data to be retrieved by unauthorized parties. This weakness categorizes as CWE‑201, where sensitive information can be disclosed by the application.

Affected Systems

Affected systems include installations of the WPDB to Sql plugin by Niket Joshi, specifically versions from the earliest available build up to and including 1.2. Any WordPress site that has not updated beyond version 1.2 of this plugin remains vulnerable.

Risk and Exploitability

The CVSS base score of 7.5 indicates high severity, and the EPSS score of less than 1% suggests that exploit attempts are currently rare. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the web application interface, where an attacker could craft requests that trigger the plugin’s response mechanism, thereby gaining access to embedded sensitive data. Additional prerequisites include that the plugin is active and that the site allows normal user interactions to be processed by the plugin’s codepath.

Generated by OpenCVE AI on May 1, 2026 at 19:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WPDB to Sql to the latest available version that eliminates the information exposure flaw
  • If an upgrade is not immediately possible, temporarily disable or uninstall the plugin to stop the data leakage path
  • Configure the web server or application firewall to block or monitor traffic patterns that could trigger the plugin’s data export functionality and ensure only authorized administrative users can access the plugin’s use

Generated by OpenCVE AI on May 1, 2026 at 19:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3407 Insertion of Sensitive Information Into Sent Data vulnerability in NotFound WPDB to Sql allows Retrieve Embedded Sensitive Data. This issue affects WPDB to Sql: from n/a through 1.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in NotFound WPDB to Sql allows Retrieve Embedded Sensitive Data. This issue affects WPDB to Sql: from n/a through 1.2. Insertion of Sensitive Information Into Sent Data vulnerability in Niket Joshi WPDB to Sql wpdb-to-sql allows Retrieve Embedded Sensitive Data.This issue affects WPDB to Sql: from n/a through <= 1.2.
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Thu, 23 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jan 2025 14:45:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in NotFound WPDB to Sql allows Retrieve Embedded Sensitive Data. This issue affects WPDB to Sql: from n/a through 1.2.
Title WordPress WPDB to Sql plugin <= 1.2 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:19.317Z

Reserved: 2025-01-16T11:30:05.455Z

Link: CVE-2025-23774

cve-icon Vulnrichment

Updated: 2025-01-23T16:50:28.188Z

cve-icon NVD

Status : Deferred

Published: 2025-01-22T15:15:23.440

Modified: 2026-04-23T15:24:29.280

Link: CVE-2025-23774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T19:45:24Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data