The CTL Behance Importer Lite WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
Metrics
Affected Vendors & Products
References
History
Thu, 02 Oct 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 02 Oct 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The CTL Behance Importer Lite WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
Title | CTL Behance Importer Lite <= 1.0 - Unauthenticated SQL Injection | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-10-02T17:31:55.463Z
Reserved: 2025-08-28T12:56:07.285Z
Link: CVE-2025-9587

Updated: 2025-10-02T17:31:50.328Z

Status : Awaiting Analysis
Published: 2025-10-02T06:15:38.443
Modified: 2025-10-02T19:11:46.753
Link: CVE-2025-9587

No data.

No data.