
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-23993 is a SQL Injection vulnerability (CWE-89) in the RiceTheme Felan Framework WordPress plugin, affecting all versions through 1.1.3. The flaw allows unauthenticated remote attackers to execute arbitrary SQL commands via insufficiently sanitized input. It was reported by researcher 0xd4rk5id3 on August 27, 2025, and publicly disclosed by Patchstack on January 8, 2026. The CNA (Patchstack) assigned a CVSS v3.1 base score of 9.3 (Critical), while CISA-ADP initially scored it 9.8 (Critical) (Patchstack).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and falls under OWASP Top 10 category A3: Injection. User-supplied input passed to the plugin's database queries is not properly sanitized or parameterized, allowing an attacker to inject arbitrary SQL syntax. No authentication is required to exploit this flaw, and no user interaction is needed, making it remotely exploitable with low attack complexity. No detailed technical write-up or public proof-of-concept code has been published as of the time of disclosure (Patchstack).
Successful exploitation allows an unauthenticated attacker to read, modify, or delete sensitive data from the WordPress site's database, potentially exposing user credentials, personal information, and site configuration. Attackers may also bypass authentication mechanisms by manipulating user records, or escalate privileges within the WordPress application. In worst-case scenarios, database administrative operations could be leveraged for further system compromise, affecting confidentiality, integrity, and availability of the affected site (Patchstack).
There is no public proof-of-concept exploit code and no confirmed in-the-wild exploitation reported as of disclosure. The EPSS score is approximately 0.021%, indicating a low current probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting WordPress plugins at scale, regardless of site popularity (Patchstack).
/wp-content/plugins/felan-framework/.') and observing database error responses or behavioral differences.wp_users table contents, including hashed passwords and email addresses, or enumerate other sensitive tables.', --, UNION, SELECT, SLEEP) in query parameters or POST body fields.wp_users table such as new administrator accounts or modified email addresses; unusual queries in database slow query logs involving UNION SELECT or INFORMATION_SCHEMA.As of the disclosure date, no official patch from RiceTheme has been released for the Felan Framework plugin. Site administrators should remove or deactivate the plugin until a patched version becomes available. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts in the interim. Additional workarounds include deploying a Web Application Firewall (WAF) with SQL injection detection rules, restricting database user permissions to the minimum necessary, and monitoring database query logs for anomalous activity (Patchstack).
The vulnerability was covered in Wordfence's weekly WordPress vulnerability report for the period of January 5–11, 2026, highlighting it among notable plugin vulnerabilities. The Hacker Wire also reported on the CVE shortly after disclosure. No significant vendor statements from RiceTheme or broader community debate have been observed beyond standard vulnerability tracking and reporting (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."