cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcleverreach-wp cleverreach-wp

Direction: ascending
Aug 06, 2025

CleverReach® WP # CVE-2025-7036

CVE, Research URL

CVE-2025-7036

Application

CleverReach® WP

Date
Aug 06, 2025
Research Description
The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all versions up to, and including, 1.5.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE-2025-49059 may be a duplicate of this issue.
Affected versions
max 1.5.21.
Status
vulnerable
Jan 27, 2026

CleverReach® WP # CVE-2025-68034

CVE, Research URL

CVE-2025-68034

Application

CleverReach® WP

Date
Jan 22, 2026
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP cleverreach-wp allows SQL Injection.This issue affects CleverReach® WP: from n/a through <= 1.5.21.
Affected versions
max 1.5.22.
Status
vulnerable
Jun 16, 2026

CleverReach® WP # CVE-2025-49059

CVE, Research URL

CVE-2025-49059

Application

CleverReach® WP

Date
Aug 14, 2025
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP cleverreach-wp allows SQL Injection.This issue affects CleverReach® WP: from n/a through <= 1.5.20.
Affected versions
max 1.5.21.
Status
vulnerable