Plugin Organizer, CVE-2025-13417
- CVE, Research URL
- Home page URL
- Application
- Published on
- Dec 29, 2025
- Research Description
- The Plugin Organizer WordPress plugin before 10.2.4 does not sanitize and escape a parameter before using it in a SQL statement, allowing subscribers to perform SQL injection attacks.
- Affected versions
-
max 10.2.4.
- Status
-
vulnerable
| Previous vulnerability researches |
|---|
| WS Force Login Page (CVE-2025-46521) , Apr 26, 2025 |