CVE-2025-14477
The 404 Solution WordPress plugin contains a vulnerability in its handling of user-supplied input, specifically the `filterText` parameter in the `ajaxUpdatePaginationLinks` AJAX action, which allows attackers to inject malicious SQL code into existing queries. This flaw can be exploited by authenticated users with administrator-level access or higher to extract sensitive database information through a time-based blind SQL injection attack. The vulnerability affects all plugin versions up to and including 3.1.0.
Based on public CVE data (MITRE/NVD).