
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-9200 is a SQL Injection vulnerability in the Blappsta Mobile App Plugin ("Your native, mobile iPhone App and Android App") for WordPress, affecting all versions up to and including 0.8.8.8. The flaw exists in the nh_ynaa_comments() function and allows unauthenticated attackers to extract sensitive information from the database. It was published on October 3, 2025, and assigned by Wordfence. The CVSS v3.1 base score is 7.5 (High) (Wordfence).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). It stems from insufficient escaping of user-supplied input and a lack of prepared statements in the nh_ynaa_comments() function, enabling attackers to append malicious SQL clauses to existing queries. No authentication or user interaction is required, and the attack is conducted entirely over the network with low complexity. No public proof-of-concept code has been identified at this time (Wordfence, WordPress Plugin Page).
Successful exploitation allows unauthenticated remote attackers to read sensitive data from the WordPress database, potentially including user credentials, email addresses, session tokens, and other confidential site content. The impact is limited to confidentiality — integrity and availability are not directly affected by this vulnerability. However, extracted credentials could enable further account takeover or lateral movement within the hosting environment (Wordfence).
No active in-the-wild exploitation has been reported for CVE-2025-9200, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.064%, indicating a low probability of exploitation in the near term. No exploit kits or weaponized code have been publicly identified. The vulnerability is exploitable by unauthenticated attackers with no special conditions, which lowers the barrier for opportunistic exploitation (Wordfence).
yournewsapp) version ≤ 0.8.8.8 using tools like WPScan, Shodan, or by checking the plugin's readme.txt file at https://target.com/wp-content/plugins/yournewsapp/readme.txt.nh_ynaa_comments() function, which handles comment-related requests from the mobile app API.UNION SELECT or time-based blind injection using SLEEP()) to enumerate database contents.sqlmap against the vulnerable endpoint to dump database tables, including WordPress wp_users for usernames and hashed passwords.yournewsapp) containing SQL metacharacters such as ', --, UNION, SELECT, or SLEEP().UNION SELECT or time-delay functions originating from the web application user.wp-content/plugins/yournewsapp/ with version ≤ 0.8.8.8 (check readme.txt for version string).The primary remediation is to update the Blappsta Mobile App Plugin to a version beyond 0.8.8.8 if a patched release is available, or to deactivate and remove the plugin entirely if no patch exists. Site administrators should verify the current plugin version via the WordPress dashboard and check the WordPress plugin page for updates. As an interim measure, consider using a Web Application Firewall (WAF) rule to block SQL injection patterns targeting the plugin's endpoints. Restricting access to the plugin's API endpoints at the server or firewall level can also reduce exposure (Wordfence).
Wordfence disclosed and assigned this CVE as part of their weekly WordPress vulnerability report for the period of September 29 – October 5, 2025, highlighting it among other plugin vulnerabilities (Wordfence Blog). No significant independent researcher commentary or broader media coverage has been identified for this specific vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."