
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69365 is a Blind SQL Injection vulnerability in the TeconceTheme Uroan Core WordPress plugin, classified under CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). It affects all versions of the Uroan Core plugin up to and including 1.4.4, and can be exploited by unauthenticated remote attackers without any user interaction. The vulnerability was published on February 20, 2026, and carries a CVSS v3.1 base score of 9.3 (Critical) (Feedly).
The root cause is improper neutralization of user-supplied input incorporated into SQL queries within the Uroan Core WordPress plugin (CWE-89), enabling blind SQL injection. Because no authentication or user interaction is required and the attack vector is network-accessible, an attacker can send crafted HTTP requests directly to vulnerable plugin endpoints. The vulnerability supports both time-based and boolean-based blind SQL injection techniques, allowing attackers to infer database contents without receiving direct query output. The changed scope in the CVSS vector indicates the impact extends beyond the plugin itself to the underlying database (Feedly).
Successful exploitation allows unauthenticated remote attackers to extract sensitive data from the WordPress site's database, including user credentials, personal data, and other confidential records, resulting in a high confidentiality impact. The vulnerability also carries a low availability impact, meaning limited service disruption is possible. Because the scope is marked as changed, the impact can extend beyond the plugin to affect the broader database environment, potentially enabling further compromise of the WordPress installation or hosted data (Feedly).
As of the latest available data, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation of CVE-2025-69365. The EPSS score is approximately 0.021%, reflecting a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly).
/wp-content/plugins/uroan-core/).' AND SLEEP(5)-- for time-based, or ' AND 1=1-- vs ' AND 1=2-- for boolean-based) and inject them into the vulnerable parameter.sqlmap with the identified endpoint and parameter to systematically extract database names, table names, and column contents.wp_users) to retrieve hashed credentials, email addresses, and other sensitive records for offline cracking or further exploitation (Feedly).SLEEP(), AND 1=1, UNION SELECT) in query parameters; high-frequency requests from a single IP suggesting automated scanning or sqlmap activity.SLEEP() or heavy conditional logic originating from the web application user.Users should update the Uroan Core plugin to a version higher than 1.4.4 as soon as a patched release becomes available from TeconceTheme. In the interim, consider deactivating or removing the plugin to eliminate the attack surface. Deploy a Web Application Firewall (WAF) with SQL injection detection rules to block malicious requests. Additionally, restrict database user permissions to the minimum required, implement rate limiting on plugin endpoints, and review database access logs for suspicious activity (Feedly).
The vulnerability was noted in the Wordfence Intelligence Weekly WordPress Vulnerability Report covering the period of January 26 to February 1, 2026, indicating it received standard industry tracking attention (Wordfence). No significant vendor statements, notable researcher commentary, or broader media coverage has been identified beyond routine vulnerability database entries.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."