CVE-2025-5287

HIGH EXPLOITED NUCLEI

Likes and Dislikes Plugin <1.0.0 - SQL Injection

Title source: llm

Description

The Likes and Dislikes Plugin plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versions up to, and including, 1.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Exploits (5)

nomisec WORKING POC 8 stars
by wiseep · infoleak
https://github.com/wiseep/CVE-2025-5287
nomisec WRITEUP 1 stars
by Nxploited · infoleak
https://github.com/Nxploited/CVE-2025-5287
nomisec WORKING POC 1 stars
by RootHarpy · infoleak
https://github.com/RootHarpy/CVE-2025-5287
nomisec WORKING POC
by RandomRobbieBF · infoleak
https://github.com/RandomRobbieBF/CVE-2025-5287
github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2025-5287

Nuclei Templates (1)

Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection
HIGHVERIFIEDby CodeStuffBreakThings

Scores

CVSS v3 7.5
EPSS 0.0803
EPSS Percentile 92.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Exploitation Intel

VulnCheck KEV 2025-07-17

Classification

CWE
CWE-89
Status draft

Timeline

Published May 28, 2025
Tracked Since Feb 18, 2026