CVE Database /
CVE-2025-48091
CVE · High
CVE-2025-48091 — AnyComment [anycomment] <= 0.3.6 (unfixed)
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-48091
|
AnyComment [anycomment] <= 0.3.6 (unfixed) |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
8.5
|
< 0.3.6
|
0.3.6 |
2025-10-08 |
—
|
CVE-2025-48091
The AnyComment plugin for WordPress is susceptible to SQL Injection in versions 0.3.6 and earlier because user input is not properly escaped and the SQL query lacks adequate preparation. Authenticated users with subscriber-level access or higher can exploit this by injecting additional SQL commands that could potentially reveal sensitive data from the database.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings