CVE-2025-24659
HIGHWordPress Download Manager Premium <5.9.6 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-24659. PoCs published by DoTTak.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2025-24659, a SQL injection vulnerability in the WordPress plugin 'Premium Packages – Sell Digital Products Securely' (versions <= 5.9.6). The exploit leverages time-based blind SQL injection via the 'orderby' parameter to extract database information.
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages allows Blind SQL Injection.This issue affects WPDM – Premium Packages: from n/a through <= 5.9.6.
Exploits (1)
This repository contains a functional proof-of-concept exploit for CVE-2025-24659, a SQL injection vulnerability in the WordPress plugin 'Premium Packages – Sell Digital Products Securely' (versions <= 5.9.6). The exploit leverages time-based blind SQL injection via the 'orderby' parameter to extract database information.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L