CVE · High

CVE-2025-48091 — AnyComment [anycomment] <= 0.3.6 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-48091 AnyComment [anycomment] <= 0.3.6 (unfixed) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.5 < 0.3.6 0.3.6 2025-10-08

CVE-2025-48091

The AnyComment plugin for WordPress is susceptible to SQL Injection in versions 0.3.6 and earlier because user input is not properly escaped and the SQL query lacks adequate preparation. Authenticated users with subscriber-level access or higher can exploit this by injecting additional SQL commands that could potentially reveal sensitive data from the database.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.