
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59557 is an unauthenticated SQL Injection vulnerability in the ThemeMove Learts Addons WordPress plugin, classified under CWE-89. It affects all versions of the plugin prior to 1.7.5 and was reported by security researcher "Bonds" on June 8, 2025, with public disclosure on October 22, 2025 via Patchstack. The vulnerability carries a CVSS v3.1 base score of 9.3 (Critical), assigned by Patchstack (Patchstack).
The vulnerability is rooted in improper neutralization of special elements used in SQL commands (CWE-89), meaning user-supplied input is passed to database queries without adequate sanitization or parameterization. Because no authentication is required (PR:N) and no user interaction is needed (UI:N), an attacker can send crafted HTTP requests directly to the vulnerable plugin endpoint to inject arbitrary SQL. The changed scope (S:C) in the CVSS vector indicates the impact can extend beyond the plugin itself to the broader WordPress database environment (Patchstack).
Successful exploitation allows an unauthenticated attacker to read sensitive database contents — including WordPress user credentials, personal data, and site configuration — and may also enable modification or deletion of database records. The changed scope means the impact is not limited to the plugin's own data but can affect the entire WordPress database. This poses significant risks to site confidentiality and integrity, and could facilitate account takeover or further compromise of the hosting environment (Patchstack).
No public proof-of-concept exploit code has been identified, and there is no confirmed evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.021% (0.000210), indicating a currently low probability of exploitation in the near term. However, Patchstack classifies this as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their traffic or popularity (Patchstack). The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
/wp-content/plugins/learts-addons/).', UNION, SELECT, --, OR 1=1) in query parameters or POST body.wpdb errors referencing SQL syntax).UNION SELECT or time-delay functions (e.g., SLEEP(), BENCHMARK()).The primary remediation is to update the Learts Addons plugin to version 1.7.5 or later, which contains the fix for this vulnerability (Patchstack). If an immediate update is not feasible, site administrators should consider temporarily disabling the plugin and deploying a Web Application Firewall (WAF) with rules targeting SQL injection patterns — Patchstack users have access to a virtual patch/mitigation rule for this CVE. Additionally, conducting a security audit of the WordPress database for signs of unauthorized access and monitoring application logs for suspicious activity are recommended interim steps.
Patchstack, the CNA that assigned and disclosed this CVE, has flagged it as high priority and noted that SQL injection vulnerabilities of this severity are frequently leveraged in mass-exploit campaigns against WordPress sites. No notable independent researcher commentary or significant media coverage beyond the Patchstack advisory has been identified at this time (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."