
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67950 is a Blind SQL Injection vulnerability in the All In One SEO Pack WordPress plugin developed by Syed Balkhi. It affects all versions up to and including 4.9.1, and was patched in version 4.9.1.1. The vulnerability was reported by researcher mcdruid on November 6, 2025, disclosed by Patchstack on December 6, 2025, and published to NVD on December 16, 2025. The CNA-assigned CVSS v3.1 base score is 8.5 (High) (Patchstack).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), enabling Blind SQL Injection attacks. Exploitation requires low-level privileges — specifically Contributor or Developer role — and no user interaction, making it exploitable remotely over the network. The attack involves injecting malicious SQL commands through unsanitized input handled by the plugin, allowing an attacker to infer database contents through boolean- or time-based blind techniques without direct query output. No public proof-of-concept or detailed technical write-up has been published as of the time of this report (Patchstack).
A low-privileged authenticated attacker (Contributor or Developer role) can exploit this vulnerability to extract sensitive data from the WordPress database, including user credentials, private content, and configuration data. The vulnerability's changed scope indicates potential impact beyond the plugin itself, potentially compromising the integrity and confidentiality of the entire WordPress site's database. Depending on database permissions, an attacker may also be able to modify or delete database contents, undermining site integrity (Patchstack).
As of the time of this report, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation. Patchstack rates the practical priority as Low, noting the issue is unlikely to be exploited imminently. The EPSS score is approximately 0.021%, reflecting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).
The vulnerability is fixed in All In One SEO Pack version 4.9.1.1. Site administrators should update the plugin immediately via the WordPress dashboard or by downloading the patched version from the WordPress plugin repository. If an immediate update is not possible, restricting Contributor and Developer role access to the plugin's functionality can reduce exposure. Deploying a Web Application Firewall (WAF) capable of detecting SQL injection patterns provides an additional layer of defense. Patchstack users can enable auto-update for vulnerable plugins to automate remediation (Patchstack).
Patchstack, the assigning CNA, classified the vulnerability as low priority and noted it is unlikely to be exploited at scale despite the high CVSS score, citing the required authenticated access as a significant barrier. The Wordfence weekly vulnerability report for December 1–7, 2025 included coverage of this issue. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."