Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-3951


The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations.


Published

2025-06-02T06:15:20.620

Last Modified

2025-06-09T20:54:55.080

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application updraftplus wp-optimize < 4.2.0 Yes

References