
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59129 is a Blind SQL Injection vulnerability in the WordPress Appointify plugin, affecting all versions up to and including 1.0.8. The flaw stems from improper neutralization of special elements used in SQL commands (CWE-89), allowing high-privileged attackers to perform blind SQL injection attacks against the underlying database. It was reported by researcher 0xVenus on October 18, 2025, and publicly disclosed by Patchstack on December 30, 2025. The vulnerability carries a CVSS v3.1 base score of 7.6 (High) (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and enables Blind SQL Injection, meaning the attacker infers database contents through boolean-based or time-based response differences rather than direct output. Exploitation requires high privileges (Administrator/Developer level) and is conducted over the network without user interaction, with a changed scope indicating impact can extend beyond the plugin itself to the broader WordPress database. No specific vulnerable endpoint or parameter has been publicly detailed in available sources, but the attack pattern aligns with CAPEC-7 (Blind SQL Injection) and CAPEC-66 (SQL Injection) (Patchstack).
Successful exploitation allows a high-privileged attacker to directly interact with the WordPress site's database, primarily resulting in high confidentiality impact through unauthorized data extraction (e.g., user credentials, personal data, appointment records). Availability is also marginally affected (low impact), while integrity is not directly impacted. Because the CVSS scope is marked as Changed, the impact can extend beyond the Appointify plugin to other data stored in the shared WordPress database (Patchstack, Red Hat CVE).
As of the disclosure date, no official patch is available for the Appointify plugin, and no public proof-of-concept exploit code has been referenced in available sources. The EPSS score is approximately 0.027%, indicating a low probability of exploitation in the near term. Patchstack classifies the priority as Low, noting the issue is unlikely to be actively exploited, and there is no indication of in-the-wild exploitation or CISA KEV catalog inclusion (Patchstack).
' AND SLEEP(5)-- or ' AND 1=1--) into the vulnerable parameter to confirm injection and infer database structure.sqlmap with appropriate authentication cookies to enumerate database tables, extract user credentials, appointment data, or other sensitive records via blind SQL injection techniques (Patchstack).', --, SLEEP, WAITFOR, AND 1=1) in query parameters or POST body.SLEEP() or BENCHMARK() functions).At the time of disclosure, no official patched version of the Appointify plugin was available; Patchstack notes there is no official patch released. Site administrators should consider deactivating and removing the Appointify plugin until a patched version (1.0.9 or later) is released. As an interim measure, restricting Administrator/Developer account access and implementing a Web Application Firewall (WAF) with SQL injection rules (such as Patchstack's virtual patching) can reduce exploitation risk (Patchstack).
The vulnerability was noted on Bluesky by TheHackerWire shortly after disclosure, and was indexed by multiple vulnerability aggregators including Vulners, VulDB, and CIRCL. Patchstack, the assigning organization, classified the issue as low priority with limited exploitation likelihood. No significant vendor statements or major media coverage beyond standard vulnerability database entries have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."