CVE · Medium

CVE-2025-14477 — 404 Solution [404-solution] < 3.1.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-14477 404 Solution [404-solution] < 3.1.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 4.9 < 3.1.1 3.1.1 2025-12-12

CVE-2025-14477

The 404 Solution WordPress plugin contains a vulnerability in its handling of user-supplied input, specifically the `filterText` parameter in the `ajaxUpdatePaginationLinks` AJAX action, which allows attackers to inject malicious SQL code into existing queries. This flaw can be exploited by authenticated users with administrator-level access or higher to extract sensitive database information through a time-based blind SQL injection attack. The vulnerability affects all plugin versions up to and including 3.1.0.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.