Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jahertor WP Featured Entries wp-featured-entries allows SQL Injection.This issue affects WP Featured Entries: from n/a through <= 1.0.
Published: 2025-03-24
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper Neutralization of Special Elements used in an SQL Command allows an attacker to inject arbitrary SQL via a vulnerable input in the WP Featured Entries plugin. This injection flaw, identified as CWE-89, enables a malicious actor to read, modify, or delete data stored in the WordPress database, potentially leading to data loss, credential theft, or other compromises of confidentiality and integrity. The vulnerability is limited to the plugin’s database interactions and does not grant system-wide privileges.

Affected Systems

The Jahertor WP Featured Entries plugin for WordPress, specifically versions 1.0 and any earlier releases, is affected. No additional version constraints are stated, so all releases up to and including 1.0 are considered vulnerable.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present; the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, exploiting an exposed input field within the plugin’s front‑end or administrative interface. It is inferred that authenticated administrative access may be required to exercise the injection, but the description does not explicitly state this requirement. Once exploited, an attacker can manipulate database content, which can compromise site integrity and expose sensitive data.

Generated by OpenCVE AI on May 1, 2026 at 04:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest release of the WP Featured Entries plugin or upgrade to a version that includes the fix.
  • If an upgrade is not possible, disable the plugin to eliminate the attack surface.
  • Ensure all user inputs to the plugin are properly sanitized or parameterized to mitigate injection risks.

Generated by OpenCVE AI on May 1, 2026 at 04:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-7940 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jahertor WP Featured Entries allows SQL Injection. This issue affects WP Featured Entries: from n/a through 1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jahertor WP Featured Entries allows SQL Injection. This issue affects WP Featured Entries: from n/a through 1.0. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jahertor WP Featured Entries wp-featured-entries allows SQL Injection.This issue affects WP Featured Entries: from n/a through <= 1.0.
Title WordPress WP Featured Entries - <= <= 1.0 SQL Injection Vulnerability WordPress WP Featured Entries plugin <= - 1.0 SQL Injection Vulnerability
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Mon, 31 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Mar 2025 14:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jahertor WP Featured Entries allows SQL Injection. This issue affects WP Featured Entries: from n/a through 1.0.
Title WordPress WP Featured Entries - <= <= 1.0 SQL Injection Vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:54.410Z

Reserved: 2025-03-24T13:00:07.996Z

Link: CVE-2025-30569

cve-icon Vulnrichment

Updated: 2025-03-31T18:22:49.687Z

cve-icon NVD

Status : Deferred

Published: 2025-03-24T14:15:28.780

Modified: 2026-06-17T09:08:56.423

Link: CVE-2025-30569

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T04:45:08Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')