Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada allows SQL Injection.This issue affects Entrada: from n/a through 5.7.7.
Published: 2026-01-05
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw exists in the WordPress Entrada theme where unsanitized input is incorporated directly into SQL statements. The resulting SQL Injection can allow an attacker to execute arbitrary database commands. Depending on database privileges, this could lead to sensitive data extraction, modification, or even escalation of privileges within the site.

Affected Systems

The vulnerability affects the Waituk Entrada Theme for WordPress, versions up through 5.7.7. Users running any of those releases are potentially exposed.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.3, indicating high severity, while the EPSS score is under 1%, suggesting that exploitation is currently unlikely but still possible. It is not listed in the CISA KEV catalog, but the inherent risk of remote injection remains. The likely attack vector is remote, via crafted requests to the WordPress site that exploit the insecure SQL handling. Creation of malicious payloads through public interfaces could trigger the flaw without additional authentication.

Generated by OpenCVE AI on April 30, 2026 at 14:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Entrada theme to a version newer than 5.7.7 to remove the vulnerable code.
  • If an upgrade cannot be applied immediately, disable or delete the Entrada theme from the WordPress installation to eliminate the attack surface.
  • Deploy a Web Application Firewall rule or similar input validation to block suspicious SQL injection payloads targeting the theme.

Generated by OpenCVE AI on April 30, 2026 at 14:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 19:45:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada entrada allows SQL Injection.This issue affects Entrada: from n/a through <= 5.7.7. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada allows SQL Injection.This issue affects Entrada: from n/a through 5.7.7.
References

Thu, 23 Apr 2026 15:30:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada allows SQL Injection.This issue affects Entrada: from n/a through 5.7.7. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada entrada allows SQL Injection.This issue affects Entrada: from n/a through <= 5.7.7.
References

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Tue, 06 Jan 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 06 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada allows SQL Injection.This issue affects Entrada: from n/a through 5.7.7.
Title WordPress Entrada Theme <= 5.7.7 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:32.644Z

Reserved: 2025-04-16T06:23:51.712Z

Link: CVE-2025-39484

cve-icon Vulnrichment

Updated: 2026-01-05T19:37:59.867Z

cve-icon NVD

Status : Deferred

Published: 2026-01-05T17:15:45.033

Modified: 2026-04-28T19:32:00.800

Link: CVE-2025-39484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T14:30:06Z

Weaknesses