Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom API for WP custom-api-for-wp allows SQL Injection.This issue affects Custom API for WP: from n/a through <= 4.2.2.
Published: 2025-08-20
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in miniOrange Custom API for WP arises from improper neutralization of special elements used in an SQL command. The plugin builds database queries that incorporate user input without adequate sanitization, resulting in a classic SQL injection flaw (CWE‑89). An attacker can supply crafted input to inject arbitrary SQL statements, potentially accessing, modifying, or deleting database data. The consequences include loss of confidentiality, data integrity, and potentially availability if the database is corrupted.

Affected Systems

The affected product is the miniOrange Custom API for WP plugin for WordPress. Versions from the earliest release through 4.2.2 are vulnerable, as indicated by the range "n/a through <= 4.2.2." No specific build suffixes or minor revisions were listed, so any release up to and including 4.2.2 may contain the flaw.

Risk and Exploitability

The CVSS score of 9.3 classifies the flaw as critical, while the EPSS score of <1% shows that, at the time of analysis, the probability of exploitation is very low but not zero. The vulnerability is not in the CISA KEV list. Because the plugin exposes API endpoints that are accessible to the public web, the likely attack vector is a remote attacker sending a malicious request to the custom API URL. No authentication requirement is mentioned in the description, so an unauthenticated attacker can craft the exploit. Given the high severity and the remote nature of the attack, administrators should treat this as an urgent threat.

Generated by OpenCVE AI on April 30, 2026 at 08:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the miniOrange Custom API for WP plugin to the latest release that contains the SQL injection fix; any version newer than 4.2.2 is expected to resolve the issue.
  • If an immediate upgrade is not possible, disable or uninstall the plugin to remove the vulnerable code path.
  • Restrict access to the plugin’s API endpoints by enforcing authentication and limiting the allowed IP ranges, and consider implementing a web application firewall that blocks SQL injection patterns.

Generated by OpenCVE AI on April 30, 2026 at 08:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28555 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom API for WP allows SQL Injection. This issue affects Custom API for WP: from n/a through 4.2.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom API for WP allows SQL Injection. This issue affects Custom API for WP: from n/a through 4.2.2. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom API for WP custom-api-for-wp allows SQL Injection.This issue affects Custom API for WP: from n/a through <= 4.2.2.
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Thu, 21 Aug 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 20 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 20 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom API for WP allows SQL Injection. This issue affects Custom API for WP: from n/a through 4.2.2.
Title WordPress Custom API for WP <= 4.2.2 - SQL Injection Vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:29.799Z

Reserved: 2025-07-16T08:52:07.076Z

Link: CVE-2025-54048

cve-icon Vulnrichment

Updated: 2025-08-20T15:09:33.896Z

cve-icon NVD

Status : Deferred

Published: 2025-08-20T08:15:47.777

Modified: 2026-04-23T15:32:46.180

Link: CVE-2025-54048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T08:45:16Z

Weaknesses