Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Appsero Helper appsero-helper allows SQL Injection.This issue affects Appsero Helper: from n/a through <= 1.3.4.
Published: 2025-04-24
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of special elements in the SQL command used by the Appsero Helper plugin allows an attacker to inject arbitrarily crafted SQL statements, potentially leading to unauthorized data exposure, modification, or even remote code execution. This weakness is identified as CWE-89 and poses a significant threat to the confidentiality, integrity, and availability of the WordPress site.

Affected Systems

The vulnerability affects the weDevs Appsero Helper plugin for WordPress, specifically versions up to and including 1.3.4. Any WordPress installation using the plugin in this range is at risk.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity level, while an EPSS score of less than 1% suggests the likelihood of exploitation is currently low, though the vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely through the web interface of the plugin, where unsanitized user input is incorporated into SQL queries, enabling attackers to send malicious payloads remotely.

Generated by OpenCVE AI on April 30, 2026 at 21:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Appsero Helper plugin to a version newer than 1.3.4 or to the latest release if available.
  • If an update is not immediately available, disable or remove the Appsero Helper plugin from the WordPress installation to eliminate the exposure.
  • Implement a web application firewall or other input validation controls to block or sanitize untrusted input before it reaches SQL statements, thereby mitigating potential injection attacks.

Generated by OpenCVE AI on April 30, 2026 at 21:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-12066 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Appsero Helper allows SQL Injection. This issue affects Appsero Helper: from n/a through 1.3.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Appsero Helper allows SQL Injection. This issue affects Appsero Helper: from n/a through 1.3.4. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Appsero Helper appsero-helper allows SQL Injection.This issue affects Appsero Helper: from n/a through <= 1.3.4.
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Fri, 25 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Appsero Helper allows SQL Injection. This issue affects Appsero Helper: from n/a through 1.3.4.
Title WordPress Appsero Helper plugin <= 1.3.4 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:29.808Z

Reserved: 2025-04-16T06:22:29.272Z

Link: CVE-2025-39377

cve-icon Vulnrichment

Updated: 2025-04-24T19:55:56.759Z

cve-icon NVD

Status : Deferred

Published: 2025-04-24T16:15:31.013

Modified: 2026-04-23T15:29:26.467

Link: CVE-2025-39377

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T21:30:36Z

Weaknesses