CVE-2025-54048
WordPress Custom API for WP <= 4.2.2 - SQL Injection Vulnerability
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom API for WP custom-api-for-wp allows SQL Injection.This issue affects Custom API for WP: from n/a through <= 4.2.2.
| CWE | CWE-89 |
| Vendor | miniorange |
| Product | custom api for wp |
| Published | Aug 20, 2025 |
| Last Updated | Apr 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for miniorange custom api for wp
Be the first to know when new unknown vulnerabilities affecting miniorange custom api for wp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
miniOrange / Custom API for WP
0 โค 4.2.2
References
Credits
Hiro (Code016Hiro) | Patchstack Bug Bounty Program