CVE-2025-13000
DB Access <= 0.8.7 - Subscriber+ SQLi
CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
15th
The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated users, such as subscriber to perform SQLI attacks
| Vendor | unknown |
| Product | db-access |
| Published | Dec 2, 2025 |
| Last Updated | Apr 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown db-access
Be the first to know when new high vulnerabilities affecting unknown db-access are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / db-access
0 โค 0.8.7
References
Credits
Yousof Nahya WPScan