| CVE ID | CVE-2025-2511 |
|---|---|
| Type | SQL Injection (SQLi) |
| Affected Component | WordPress Plugin AHAthat |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
| CVSS Score | 4.9 β Medium |
| Discovered by | Seckhmet |
A SQL Injection vulnerability was identified in the WordPress plugin AHAthat. This flaw allows an attacker with administrator privileges (PR:H) to manipulate SQL queries and exfiltrate sensitive data from the WordPress database.
Although exploitation requires elevated rights, the impact on confidentiality is critical (C:H), potentially leading to the disclosure of user data, credentials, or sensitive information stored in the database.
Update the AHAthat plugin to the patched version. Apply the principle of least privilege on WordPress administrator accounts. Use prepared statements for all database interactions on the developer side.