Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in web-mv ResAds resads allows SQL Injection.This issue affects ResAds: from n/a through <= 2.0.5.
Published: 2025-01-16
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in the web-mv ResAds plugin allows attackers to inject arbitrary SQL through properly crafted input. The flaw affects all releases up to and including version 2.0.5. Successful exploitation could read, modify, or delete database data, compromising the site’s content and potentially exposing sensitive user information.

Affected Systems

The vulnerability exists in ResAds developed by web‑mv. Any WordPress site that has ResAds 2.0.5 or earlier installed is impacted; versions newer than 2.0.5 are not affected.

Risk and Exploitability

The CVSS score of 7.6 denotes high severity, while the EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, likely through unauthenticated HTTP requests to a plugin endpoint that accepts user input, and compromise would result in loss of confidentiality and integrity for the site’s database contents.

Generated by OpenCVE AI on May 2, 2026 at 06:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ResAds to a version newer than 2.0.5 when it becomes available.
  • If an upgrade is not immediately available, disable or uninstall the ResAds plugin to eliminate the vulnerability.
  • Configure a web application firewall or database firewall to detect and block suspicious SQL patterns targeting ResAds endpoints.
  • Limit the privileges of the database user used by WordPress to only the minimum necessary for normal operation.

Generated by OpenCVE AI on May 2, 2026 at 06:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3412 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in web-mv.de ResAds allows SQL Injection.This issue affects ResAds: from n/a through 2.0.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in web-mv.de ResAds allows SQL Injection.This issue affects ResAds: from n/a through 2.0.5. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in web-mv ResAds resads allows SQL Injection.This issue affects ResAds: from n/a through <= 2.0.5.
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Fri, 17 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in web-mv.de ResAds allows SQL Injection.This issue affects ResAds: from n/a through 2.0.5.
Title WordPress ResAds Plugin <= 2.0.5 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:19.844Z

Reserved: 2025-01-16T11:30:05.455Z

Link: CVE-2025-23779

cve-icon Vulnrichment

Updated: 2025-01-17T17:18:47.076Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T21:15:19.640

Modified: 2026-06-17T08:57:08.383

Link: CVE-2025-23779

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T06:15:06Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')