4.9
CVSSv3

CVE-2025-2478

CVSSv4: NA | CVSSv3: 4.9 | CVSSv2: NA | VMScore: 590 | EPSS: 0.00044 | KEV: Not Included
Published: 22/03/2025 Updated: 22/03/2025

Vulnerability Summary

WordPress Code Clone Plugin SQL Injection Vulnerability in Snippets Management

The Code Clone plugin for WordPress contains a time-based SQL Injection vulnerability through the 'snippetId' parameter in versions up to and including 0.9. The issue stems from improper parameter escaping and inadequate SQL query preparation. Authenticated attackers possessing Administrator-level privileges can manipulate the parameter to append additional SQL queries. These modified queries enable potential extraction of sensitive information directly from the database, posing a significant security risk to WordPress sites using this plugin.

Vulnerable Product Search on Vulmon Subscribe to Product

allhart code clone