Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes allows SQL Injection. This issue affects WP Pipes: from n/a through 1.4.3.
Published: 2025-07-16
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper neutralization of special elements in an SQL command, allowing an attacker to inject arbitrary SQL through the WP Pipes plugin. This could enable reading, modifying, or deleting user data, compromise authentication, and potentially disrupt site functionality, affecting confidentiality, integrity, and availability.

Affected Systems

The vulnerability affects the ThimPress WP Pipes plugin for WordPress installations utilizing any version up to and including 1.4.3. All installations of WP Pipes that have not applied the latest update are susceptible.

Risk and Exploitability

With a CVSS score of 9.3, the risk is high, but the EPSS score of less than 1% indicates that exploitation is currently unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require a user to supply crafted input to the plugin, which in practice could occur through the plugin’s public or authenticated input interfaces. A successful attack could give an adversary full control of the WordPress database linked to the site.

Generated by OpenCVE AI on May 1, 2026 at 06:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Pipes plugin to a fixed version (1.4.4 or later) following the vendor release notes or the official WordPress repository. Any version above 1.4.3 is not affected by this flaw.
  • If an immediate upgrade is not feasible, deactivate the WP Pipes plugin to eliminate the vulnerable code. This can be done via the WordPress admin dashboard or by renaming the plugin directory on the server.
  • Perform a database audit for suspicious user accounts, foreign keys, or unauthorized table modifications, and enable monitoring of database error logs or web server logs to detect any prior compromise.

Generated by OpenCVE AI on May 1, 2026 at 06:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-21604 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes allows SQL Injection. This issue affects WP Pipes: from n/a through 1.4.3.
History

Tue, 28 Apr 2026 19:30:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes wp-pipes allows SQL Injection.This issue affects WP Pipes: from n/a through <= 1.4.3. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes allows SQL Injection. This issue affects WP Pipes: from n/a through 1.4.3.
References

Thu, 23 Apr 2026 15:30:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes allows SQL Injection. This issue affects WP Pipes: from n/a through 1.4.3. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes wp-pipes allows SQL Injection.This issue affects WP Pipes: from n/a through <= 1.4.3.
References

Wed, 26 Nov 2025 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:thimpress:wp_pipes:*:*:*:*:*:wordpress:*:*

Wed, 16 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00028}


Wed, 16 Jul 2025 11:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes allows SQL Injection. This issue affects WP Pipes: from n/a through 1.4.3.
Title WordPress WP Pipes plugin <= 1.4.3 - SQL Injection Vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Thimpress Wp Pipes
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:52.496Z

Reserved: 2025-03-11T08:10:36.161Z

Link: CVE-2025-28982

cve-icon Vulnrichment

Updated: 2025-07-16T13:41:26.221Z

cve-icon NVD

Status : Modified

Published: 2025-07-16T12:15:24.383

Modified: 2026-04-28T19:30:11.933

Link: CVE-2025-28982

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T07:00:06Z

Weaknesses