Vulnerability Description
The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated users, such as subscriber to perform SQLI attacks
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jimbob1953 | Db-Access | <= 0.8.7 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/aec53f87-6500-4c8a-925a-146be61bbabf/ExploitThird Party Advisory
FAQ
What is CVE-2025-13000?
CVE-2025-13000 is a vulnerability with a CVSS score of 7.7 (HIGH). The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated users, such as subscriber to perform SQLI attacks
How severe is CVE-2025-13000?
CVE-2025-13000 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-13000?
Check the references section above for vendor advisories and patch information. Affected products include: Jimbob1953 Db-Access.