CVE-2025-1323 is a critical SQL Injection vulnerability affecting all versions up to and including 16.26.10 of the WP-Recall plugin for WordPress. This flaw, stemming from insufficient input sanitization and improper SQL query preparation, allows unauthenticated attackers to manipulate database queries. With a CVSS score of 9.8 (CRITICAL), it presents a high risk of complete compromise of confidentiality, integrity, and availability. While not yet in the KEV catalog, exploit intelligence indicates the availability of Nuclei templates for this vulnerability, and it has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.26.12CPE matchmatch criteria | cpe:2.3:a:plechevandrey:wp-recall:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.