CVE-2025-59557
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-59557 is an unauthenticated SQL Injection vulnerability in the ThemeMove Learts Addons WordPress plugin, classified under CWE-89. It affects all versions of the plugin prior to 1.7.5 and was reported by security researcher "Bonds" on June 8, 2025, with public disclosure on October 22, 2025 via Patchstack. The vulnerability carries a CVSS v3.1 base score of 9.3 (Critical), assigned by Patchstack (Patchstack).

Technical details

The vulnerability is rooted in improper neutralization of special elements used in SQL commands (CWE-89), meaning user-supplied input is passed to database queries without adequate sanitization or parameterization. Because no authentication is required (PR:N) and no user interaction is needed (UI:N), an attacker can send crafted HTTP requests directly to the vulnerable plugin endpoint to inject arbitrary SQL. The changed scope (S:C) in the CVSS vector indicates the impact can extend beyond the plugin itself to the broader WordPress database environment (Patchstack).

Impact

Successful exploitation allows an unauthenticated attacker to read sensitive database contents — including WordPress user credentials, personal data, and site configuration — and may also enable modification or deletion of database records. The changed scope means the impact is not limited to the plugin's own data but can affect the entire WordPress database. This poses significant risks to site confidentiality and integrity, and could facilitate account takeover or further compromise of the hosting environment (Patchstack).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no confirmed evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.021% (0.000210), indicating a currently low probability of exploitation in the near term. However, Patchstack classifies this as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their traffic or popularity (Patchstack). The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Learts Addons plugin (versions < 1.7.5) using tools like WPScan, Shodan, or by inspecting plugin directories (/wp-content/plugins/learts-addons/).
  2. Identify vulnerable endpoint: Locate the specific plugin endpoint or parameter that processes unsanitized user input and passes it to a SQL query (exact endpoint details are not publicly disclosed).
  3. Craft SQL injection payload: Construct a malicious SQL payload (e.g., using UNION-based, error-based, or time-based blind injection techniques) to extract data from the WordPress database.
  4. Send unauthenticated request: Submit the crafted HTTP request to the vulnerable endpoint without any authentication credentials.
  5. Extract sensitive data: Retrieve WordPress user table contents (usernames, hashed passwords, emails) or other sensitive database records for further exploitation such as credential cracking or account takeover (Patchstack).

Indicators of compromise

  • Network: Unusual HTTP requests to WordPress endpoints associated with the Learts Addons plugin containing SQL metacharacters (e.g., single quotes ', UNION, SELECT, --, OR 1=1) in query parameters or POST body.
  • Logs: WordPress or web server access logs showing repeated requests to plugin-specific URLs with anomalous parameter values; database error messages logged by WordPress (e.g., wpdb errors referencing SQL syntax).
  • Database: Unexpected queries in database slow query logs or general query logs involving UNION SELECT or time-delay functions (e.g., SLEEP(), BENCHMARK()).
  • Application: Sudden appearance of new WordPress admin accounts or changes to existing user credentials not initiated by legitimate administrators.

Mitigation and workarounds

The primary remediation is to update the Learts Addons plugin to version 1.7.5 or later, which contains the fix for this vulnerability (Patchstack). If an immediate update is not feasible, site administrators should consider temporarily disabling the plugin and deploying a Web Application Firewall (WAF) with rules targeting SQL injection patterns — Patchstack users have access to a virtual patch/mitigation rule for this CVE. Additionally, conducting a security audit of the WordPress database for signs of unauthorized access and monitoring application logs for suspicious activity are recommended interim steps.

Community reactions

Patchstack, the CNA that assigned and disclosed this CVE, has flagged it as high priority and noted that SQL injection vulnerabilities of this severity are frequently leveraged in mass-exploit campaigns against WordPress sites. No notable independent researcher commentary or significant media coverage beyond the Patchstack advisory has been identified at this time (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78570CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78568CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78572HIGH8.1
  • kalles-addons
NoNoAug 25, 2026
CVE-2026-78576HIGH7.5
  • readabler
NoYesAug 25, 2026
CVE-2026-76128MEDIUM6.4
  • ecommerce-product-catalog
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management