
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-39484 is a critical SQL Injection vulnerability (CWE-89) in the Waituk Entrada WordPress theme, affecting all versions through 5.7.7. The vulnerability was reported by researcher "Bonds" on December 19, 2024, and published by Patchstack on May 22, 2025, with the CVE formally recorded on January 5, 2026. It carries a CVSS v3.1 base score of 9.3 (Critical), assigned by Patchstack (Patchstack DB). As of the time of writing, no official patch from the vendor is available (Patchstack DB).
The vulnerability stems from improper neutralization of user-supplied input before it is incorporated into SQL queries (CWE-89), classified under OWASP Top 10 category A3: Injection. An unauthenticated remote attacker can craft malicious HTTP requests containing SQL metacharacters or commands that are passed directly to the database without sanitization or parameterization. The attack vector is network-based, requires no privileges or user interaction, and has low attack complexity, making it trivially exploitable at scale. The changed scope in the CVSS vector indicates that the impact can extend beyond the vulnerable component itself (Patchstack DB).
Successful exploitation allows an unauthenticated attacker to execute arbitrary SQL commands against the underlying database, resulting in high confidentiality impact — including unauthorized access to and exfiltration of sensitive data such as user credentials, personal information, and site content. A low availability impact is also present, meaning the attacker could cause limited service disruption. The changed scope indicates potential for impact beyond the WordPress application itself, such as accessing data from other database schemas or facilitating further lateral movement within the hosting environment (Patchstack DB, Red Hat CVE).
' OR 1=1--, UNION-based, or time-based blind payloads) targeting the vulnerable parameter.', --, UNION, SELECT, OR 1=1) in query parameters; high volume of requests from a single IP targeting theme-specific URLs.No official patch from the Waituk vendor is currently available for the Entrada theme. As an immediate workaround, Patchstack has issued a virtual patching rule that blocks exploitation attempts for users of its service — deploying a Web Application Firewall (WAF) with SQL injection rules is strongly recommended for all affected sites. Site owners should implement input validation and parameterized queries (prepared statements) at the code level, apply the principle of least privilege to database accounts used by WordPress, and monitor for signs of exploitation. If the theme cannot be updated or replaced, consider disabling it until a patched version is released (Patchstack DB).
The vulnerability received coverage from The Hacker Wire and was noted across security-focused social media platforms including Bluesky and Mastodon (infosec.exchange). Patchstack, the discovering and reporting organization, highlighted the mass-exploit campaign risk associated with critical WordPress theme vulnerabilities of this severity. No significant vendor statement from Waituk has been publicly issued (Patchstack DB).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."