Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xavi Ivars XV Random Quotes xv-random-quotes allows SQL Injection.This issue affects XV Random Quotes: from n/a through <= 2.0.0.
Published: 2025-04-01
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an SQL injection flaw (CWE‑89) that allows an attacker to inject malicious SQL through the XV Random Quotes plugin. If exploited, the attacker could read, modify, or delete data in the WordPress database, which would compromise confidentiality, integrity, and potentially availability of the site.

Affected Systems

Affected is the XV Random Quotes plugin developed by Xavi Ivars, versions up to and including 2.0.0. WordPress sites running any of these versions are impacted.

Risk and Exploitability

The CVSS score of 9.3 indicates a high‑severity risk, and the EPSS score of less than 1% suggests a low probability of current exploitation, although the vulnerability is not listed in KEV. An attacker would likely send a crafted HTTP request containing malicious input to the plugin’s endpoint to exploit the flaw.

Generated by OpenCVE AI on May 1, 2026 at 02:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade XV Random Quotes to the latest version (≥ 2.0.1) provided by the vendor.
  • If an update is unavailable, disable or uninstall the plugin until a secure version is released.
  • Monitor database and application logs for anomalous activity and restrict admin access as needed.

Generated by OpenCVE AI on May 1, 2026 at 02:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9080 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xavi Ivars XV Random Quotes allows SQL Injection. This issue affects XV Random Quotes: from n/a through 1.40.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xavi Ivars XV Random Quotes allows SQL Injection. This issue affects XV Random Quotes: from n/a through 1.40. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xavi Ivars XV Random Quotes xv-random-quotes allows SQL Injection.This issue affects XV Random Quotes: from n/a through <= 2.0.0.
Title WordPress XV Random Quotes plugin <= 1.40 - SQL Injection vulnerability WordPress XV Random Quotes plugin <= 2.0.0 - SQL Injection vulnerability
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Tue, 01 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 05:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xavi Ivars XV Random Quotes allows SQL Injection. This issue affects XV Random Quotes: from n/a through 1.40.
Title WordPress XV Random Quotes plugin <= 1.40 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:02.292Z

Reserved: 2025-03-26T09:22:27.938Z

Link: CVE-2025-30971

cve-icon Vulnrichment

Updated: 2025-04-01T13:35:46.856Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T06:15:55.543

Modified: 2026-04-23T15:27:25.620

Link: CVE-2025-30971

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T02:45:06Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')