Description
Cross-Site Request Forgery (CSRF) vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup elisqlreports allows SQL Injection.This issue affects EZ SQL Reports Shortcode Widget and DB Backup: from n/a through <= 5.25.08.
Published: 2025-03-27
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a Cross‑Site Request Forgery that allows an attacker to inject arbitrary SQL statements into the WordPress database. When a forged request is sent to the plugin’s endpoints, the user input is directly used in a database query without proper sanitization, which can expose, modify, or delete data stored by the site. The vulnerability can compromise sensitive information, corrupt backups, and undermine the integrity of the site’s database.

Affected Systems

The Eli EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress, versions 5.25.08 and all earlier releases, is affected. Only installations running a vulnerable version are at risk.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests a low but non‑zero probability of exploitation in the wild. The CVE is not listed in the CISA KEV catalog, implying no publicly known exploits have been detected yet. The attack vector relies on a forged request that a user with access to the plugin’s functionality could trigger, and the flaw does not require additional privileges beyond those needed to use the plugin. The risk is therefore elevated by the potential impact on database integrity, but the low EPSS indicates that active exploitation is currently unlikely. Monitoring for new exploit code and rapid patching remain recommended.

Generated by OpenCVE AI on May 1, 2026 at 13:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patched version of the Eli EZ SQL Reports Shortcode Widget and DB Backup plugin (5.25.09 or later).
  • If a patch cannot be applied immediately, hide or disable the plugin’s admin interface and shortcode functionality to the public, restricting access to trusted administrators only.
  • Deploy a web‑application firewall rule that blocks suspicious or unauthorized POST requests targeting the plugin’s endpoints as a temporary protection.

Generated by OpenCVE AI on May 1, 2026 at 13:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8385 Cross-Site Request Forgery (CSRF) vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup allows SQL Injection. This issue affects EZ SQL Reports Shortcode Widget and DB Backup: from n/a through 5.25.08.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup allows SQL Injection. This issue affects EZ SQL Reports Shortcode Widget and DB Backup: from n/a through 5.25.08. Cross-Site Request Forgery (CSRF) vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup elisqlreports allows SQL Injection.This issue affects EZ SQL Reports Shortcode Widget and DB Backup: from n/a through <= 5.25.08.
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L'}


Thu, 27 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup allows SQL Injection. This issue affects EZ SQL Reports Shortcode Widget and DB Backup: from n/a through 5.25.08.
Title WordPress EZ SQL Reports Shortcode Widget and DB Backup plugin <= 5.25.08 - CSRF to SQL Injection vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:57.299Z

Reserved: 2025-03-26T09:20:11.232Z

Link: CVE-2025-30788

cve-icon Vulnrichment

Updated: 2025-03-27T13:59:23.805Z

cve-icon NVD

Status : Deferred

Published: 2025-03-27T11:15:40.093

Modified: 2026-04-23T15:27:04.267

Link: CVE-2025-30788

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T13:15:20Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)