Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle WP Full Stripe Free wp-full-stripe-free allows SQL Injection.This issue affects WP Full Stripe Free: from n/a through <= 8.2.5.
Published: 2025-09-05
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An SQL Injection vulnerability exists in the Themeisle WP Full Stripe Free plugin when it attempts to construct SQL queries without proper neutralization of special characters. A malicious attacker can exploit this flaw to read, modify, or delete database records, potentially compromising confidentiality and integrity of the site’s data and affecting the entire WordPress installation.

Affected Systems

WordPress sites that run the Themeisle WP Full Stripe Free plugin version 8.2.5 or older are affected. The issue applies to all installations using any of those vulnerable plugin releases.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.6, indicating high severity. The EPSS score is below 1%, suggesting that the probability of exploitation is low at present, and it has not been listed in the CISA KEV catalog. Attackers can likely reach the vulnerability via the plugin’s user-facing interfaces, meaning the attack vector is remote, but the lack of high exploit prevalence reduces immediate risk.

Generated by OpenCVE AI on April 30, 2026 at 02:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Full Stripe Free plugin to version 8.3.0 or later, which contains the fix for the SQL injection flaw.
  • Verify that any custom modifications or extensions to the plugin have been updated to match the latest secure codebase.
  • Restrict database user privileges to the minimum required for the plugin, limiting potential damage if an injection occurs.

Generated by OpenCVE AI on April 30, 2026 at 02:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26988 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle WP Full Stripe Free allows SQL Injection. This issue affects WP Full Stripe Free: from n/a through 8.3.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle WP Full Stripe Free allows SQL Injection. This issue affects WP Full Stripe Free: from n/a through 8.3.0. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle WP Full Stripe Free wp-full-stripe-free allows SQL Injection.This issue affects WP Full Stripe Free: from n/a through <= 8.2.5.
Title WordPress WP Full Stripe Free Plugin <= 8.3.0 - SQL Injection Vulnerability WordPress WP Full Stripe Free Plugin <= 8.2.5 - SQL Injection Vulnerability
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Mon, 08 Sep 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Sep 2025 14:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle WP Full Stripe Free allows SQL Injection. This issue affects WP Full Stripe Free: from n/a through 8.3.0.
Title WordPress WP Full Stripe Free Plugin <= 8.3.0 - SQL Injection Vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-13T00:12:10.067Z

Reserved: 2025-09-05T10:48:52.285Z

Link: CVE-2025-58789

cve-icon Vulnrichment

Updated: 2025-09-08T16:42:58.425Z

cve-icon NVD

Status : Deferred

Published: 2025-09-05T14:15:47.167

Modified: 2026-04-23T15:33:38.320

Link: CVE-2025-58789

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T02:45:16Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')