Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS apartment-management allows SQL Injection.This issue affects WPAMS: from n/a through <= 44.0 (17-08-2023).
Published: 2025-05-19
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An SQL Injection vulnerability exists in the WPAMS apartment‑management plugin for WordPress due to improper neutralization of special elements used in SQL commands, a flaw categorized as CWE‑89. The flaw allows an attacker to inject arbitrary SQL statements into database queries, potentially leading to unauthorized data disclosure, modification, or deletion. The description states the issue allows SQL Injection, indicating that, if exploited, the attacker could gain extensive control over the database content and compromise the confidentiality, integrity, and availability of the application data.

Affected Systems

The plugin affected is WPAMS apartment‑management for WordPress, from its initial release through version 44.0 released 17‑08‑2023. Any WordPress site running that plugin or any earlier revision is vulnerable.

Risk and Exploitability

The CVSS score of 9.3 reflects a very high severity, and the EPSS score of less than 1% indicates that, at the moment of analysis, exploitation attempts are rare or low‑probability, but the potential impact remains significant. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves supplying crafted input to the plugin’s interface; specific authentication prerequisites are not detailed, so it is prudent to treat the vulnerability as exploitable by an attacker who can interact with the plugin’s functionality.

Generated by OpenCVE AI on May 1, 2026 at 08:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WPAMS to the latest available version (any release newer than 44.0).
  • If an upgrade is not immediately possible, disable or remove the WPAMS plugin until a fixed version is released.
  • Apply a Web Application Firewall rule to block suspicious SQL injection patterns targeting WPAMS URLs or restrict administrative access to the plugin to trusted personnel only.

Generated by OpenCVE AI on May 1, 2026 at 08:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-15768 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS allows SQL Injection.This issue affects WPAMS: from n/a through 44.0 (17-08-2023).
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS allows SQL Injection.This issue affects WPAMS: from n/a through 44.0 (17-08-2023). Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS apartment-management allows SQL Injection.This issue affects WPAMS: from n/a through <= 44.0 (17-08-2023).
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Mon, 19 May 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 19 May 2025 19:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS allows SQL Injection.This issue affects WPAMS: from n/a through 44.0 (17-08-2023).
Title WordPress WPAMS plugin <= 44.0 (17-08-2023) - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:30.259Z

Reserved: 2025-04-16T06:22:42.847Z

Link: CVE-2025-39395

cve-icon Vulnrichment

Updated: 2025-05-19T21:12:58.890Z

cve-icon NVD

Status : Deferred

Published: 2025-05-19T20:15:25.167

Modified: 2026-04-23T15:29:28.313

Link: CVE-2025-39395

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T08:30:12Z

Weaknesses