๐Ÿ” CVE Alert

CVE-2025-13000

HIGH 7.7

DB Access <= 0.8.7 - Subscriber+ SQLi

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
15th

The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated users, such as subscriber to perform SQLI attacks

Vendor unknown
Product db-access
Published Dec 2, 2025
Last Updated Apr 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown db-access

Be the first to know when new high vulnerabilities affecting unknown db-access are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / db-access
0 โ‰ค 0.8.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/aec53f87-6500-4c8a-925a-146be61bbabf/

Credits

Yousof Nahya WPScan