Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP cleverreach-wp allows SQL Injection.This issue affects CleverReach® WP: from n/a through <= 1.5.20.
Published: 2025-08-14
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper neutralization of special elements used in an SQL command, which permits an attacker to inject arbitrary SQL queries into the WordPress database when the CleverReach WP plugin processes input. This can lead to unauthorized reading or modification of database contents, potentially exposing sensitive data or corrupting the site’s integrity. The weakness is categorized as CWE‑89, a classic SQL injection vulnerability.

Affected Systems

WordPress sites that have the CleverReach WP plugin installed at versions 1.5.20 or earlier are affected. The plugin is distributed by CleverReach and operates within the WordPress environment, so any site using these versions can be compromised if the vulnerability is exploited.

Risk and Exploitability

The CVSS score of 9.3 places the issue in the critical severity range, indicating that exploitation could have far‑reaching consequences. The EPSS score of < 1% suggests that, as of now, the estimated probability of exploitation is very low, and the vulnerability is not listed in the CISA KEV catalog. The official description does not state an authentication requirement, so it is inferred that the attack may be feasible without prior user credentials; the most likely attack vector is an HTTP request that triggers the vulnerable plugin code, though the exact mechanism is not detailed in the CVE entry.

Generated by OpenCVE AI on April 30, 2026 at 16:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the CleverReach WP plugin to version 1.5.21 or later to apply the vendor fix for the SQL injection flaw.
  • If the upgrade cannot be performed immediately, remove or disable the plugin to eliminate the vulnerable code path.
  • As an interim defensive measure, restrict or block external HTTP requests that reach the plugin’s endpoints and apply server‑side input validation or parameterized queries to mitigate injection risk.

Generated by OpenCVE AI on April 30, 2026 at 16:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-24766 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP allows SQL Injection. This issue affects CleverReach® WP: from n/a through 1.5.20.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP allows SQL Injection. This issue affects CleverReach® WP: from n/a through 1.5.20. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP cleverreach-wp allows SQL Injection.This issue affects CleverReach® WP: from n/a through <= 1.5.20.
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Thu, 14 Aug 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 14 Aug 2025 10:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP allows SQL Injection. This issue affects CleverReach® WP: from n/a through 1.5.20.
Title WordPress CleverReach® WP Plugin <= 1.5.20 - SQL Injection Vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:58.596Z

Reserved: 2025-05-30T14:04:42.919Z

Link: CVE-2025-49059

cve-icon Vulnrichment

Updated: 2025-08-14T18:52:05.476Z

cve-icon NVD

Status : Deferred

Published: 2025-08-14T11:15:38.437

Modified: 2026-04-23T15:31:15.443

Link: CVE-2025-49059

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T16:30:16Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')