Sceawere

Vulnerability Detail

CVE-2026-25434UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP2LEADS Subscriber SQL Injection

Vulnerability Metadata

Severity
High
Score / CVSS
8.5
Creation Date
16h ago
Vendor
Tobias @Saleswonder.biz
Product
WP2LEADS
Attack Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Subscriber SQL Injection in WP2LEADS <= 3.5.7 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.5",
  "pubDate": "2026-10-06T09:17:41.930Z",
  "pubdate": "2026-10-06T09:17:41.930Z",
  "executiveSummary": "The WP2LEADS plugin for WordPress, specifically versions 3.5.7 and earlier, contains a critical SQL injection vulnerability. This flaw resides in the input handling mechanisms accessible to authenticated users with subscriber-level privileges.\nThe vulnerability allows an attacker to manipulate backend database queries by injecting malicious SQL statements into vulnerable parameters. An authenticated user can leverage this to bypass security controls, perform unauthorized data exfiltration, modify database content, or potentially elevate privileges within the WordPress environment.\nThe impact is significant, as it exposes the underlying database to direct manipulation, potentially leading to a complete compromise of the site's data integrity and confidentiality. Exploitation requires active authentication, but the low barrier to entry for subscriber accounts makes this a notable risk for multisite or open-registration WordPress installations. Immediate remediation is required to prevent unauthorized database interactions.",
  "technicalDetails": "The vulnerability manifests as a classic SQL injection flaw due to insufficient input validation and improper sanitization of user-supplied data before incorporating it into SQL queries. The plugin fails to use prepared statements or parameterized queries when interacting with the database, allowing an attacker to break out of the intended query structure.\nThe attack flow begins with the attacker establishing a valid session with subscriber-level privileges. By intercepting or crafting requests sent to the vulnerable plugin endpoints, the attacker introduces specially crafted SQL payloads into the input parameters. Because the application processes these parameters directly into database queries, the database engine executes the injected SQL commands with the privileges of the database user configured for the WordPress site.\nA typical exploitation sequence involves the use of UNION-based SQL injection techniques. By injecting a UNION SELECT statement, the attacker can append results from other database tables (such as the wp_users table) to the legitimate output of the plugin's query. This enables the unauthorized extraction of sensitive information, including password hashes, session tokens, and administrative configuration details.\nFurthermore, the vulnerability may permit blind SQL injection techniques, where the attacker infers database content by observing differences in the application's response behavior or execution time. This allows for the iterative extraction of data even when direct output is not returned in the browser.\nThe vulnerable component involves the server-side handling of user-submitted requests within the plugin's functional logic, specifically where database interaction occurs. Since the vulnerability is reachable by any authenticated subscriber, the attack surface is exposed to any user permitted to register an account on the platform. The post-exploitation impact includes unauthorized data modification, such as updating administrative credentials, or executing arbitrary administrative actions if the injection allows for stacked queries, depending on the server's database configuration."
}
CVE-2026-25434: WP2LEADS Subscriber SQL Injection (HIGH Severity, CVSS: 8.5) | Sceawere