
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69338 is a Blind SQL Injection vulnerability in the Riode Core WordPress plugin developed by don-themes. It stems from improper neutralization of special elements used in SQL commands (CWE-89) and allows unauthenticated, remote attackers to extract sensitive database contents. All versions of Riode Core through 1.6.26 are affected. The vulnerability was published on March 5, 2026, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 9.3 (Critical) (Feedly, Patchstack).
The vulnerability is classified under CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The flaw exists within the Riode Core plugin's handling of user-supplied input, which is passed unsanitized into SQL queries, enabling blind SQL injection. Because no authentication, user interaction, or elevated privileges are required, an attacker can send crafted network requests directly to the vulnerable endpoint to infer database contents through boolean- or time-based blind techniques. The scope is marked as Changed, indicating the impact extends beyond the vulnerable component itself (Feedly, Patchstack).
Successful exploitation allows an unauthenticated remote attacker to extract sensitive data from the underlying WordPress database, including user credentials, personal information, API keys, and other confidential content stored by the site. The CVSS scoring reflects a high confidentiality impact and a low availability impact, with no direct integrity impact. Because the scope is marked as Changed, the vulnerability's effects can extend beyond the plugin itself to the broader WordPress installation and potentially the hosting environment (Feedly).
No public proof-of-concept (PoC) exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time. The vulnerability requires no authentication and no user interaction, making it trivially exploitable by any network-accessible attacker if a PoC becomes available. The EPSS score is approximately 0.021%, indicating a currently low probability of exploitation in the near term. CVE-2025-69338 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
inurl:/wp-content/plugins/riode-core/).AND 1=1 vs. AND 1=2) and observe differences in the application's response to confirm the injection point.SLEEP(5)) or boolean-based blind SQL injection payloads — or automate with tools like sqlmap — to enumerate database names, tables, and columns.wp_users) to obtain hashed passwords, email addresses, and other sensitive records, which can then be used for credential attacks or further compromise (Feedly)./wp-admin/admin-ajax.php) or plugin-specific URLs with SQL metacharacters (', --, SLEEP, BENCHMARK, AND 1=) in query parameters or POST body.%27, %20AND%20, SLEEP%28).SLEEP() or BENCHMARK()) originating from the web application user.Site administrators running Riode Core version 1.6.26 or earlier should update to a patched version immediately once one is released by don-themes. As interim mitigations: deploy a Web Application Firewall (WAF) with SQL injection detection rules (e.g., Cloudflare, Wordfence, or Sucuri) to block malicious requests; enforce parameterized queries and input validation at the application layer; restrict database user privileges to the minimum required; and monitor database and web server logs for anomalous query patterns. Given the critical CVSS score of 9.3 and the zero-authentication requirement, this vulnerability should be treated as high priority (Feedly, Patchstack).
The vulnerability was reported by Patchstack, a WordPress security platform, and received brief coverage from The Hacker Wire. Social media activity was limited, with a mention on Mastodon via The Hacker Wire's account. No significant vendor statements or broader community debate have been observed beyond initial disclosure (The Hacker Wire).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."