CVE-2025-4578
CRITICALFile Provider WordPress Plugin < 1.2.3 - Unauthenticated SQL Injection via AJAX Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-4578. PoCs published by RandomRobbieBF.
AI-analyzed exploit summary This repository contains a proof-of-concept for CVE-2025-4578, an unauthenticated SQL injection vulnerability in the File Provider WordPress plugin (versions up to 1.2.3). The PoC uses sqlmap to demonstrate exploitation via the 'fileId' parameter, confirming time-based blind and UNION-based SQL injection techniques.
Description
The File Provider WordPress plugin through 1.2.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
Exploits (1)
This repository contains a proof-of-concept for CVE-2025-4578, an unauthenticated SQL injection vulnerability in the File Provider WordPress plugin (versions up to 1.2.3). The PoC uses sqlmap to demonstrate exploitation via the 'fileId' parameter, confirming time-based blind and UNION-based SQL injection techniques.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H