WP SQLi APR 2025 | WP SQL Injections
Managed WP/Woo Security Report
Be informed about the latest WP SQL Injections, identified and reported publicly. WP SQLi APR 2025 is a +30% INCREASE compared to previous month, as specifically targeted SQL Injections. Consider for your online safety, a managed WP/Woo Security AUDIT, – OR – switching with a TOP10LIST alternative WP Security Plugin - OR - Hire professionals for managed WP Security.
The following cases made headlines PUBLICLY just last month in the WP SQLi APR 2025 & WP SQL Injections category:
Ads by WPQuads | SQL Injection (SQLi) |
AHAthat | SQL Injection (SQLi) from id Parameter |
AnalyticsWP | Unauthenticated SQL Injection (SQLi) |
ArielBrailovsky-ViralAd | Unauthenticated SQL Injection (SQLi) |
Automation By Autonami | Unauthenticated SQL Injection (SQLi) from 'automationId' |
Awesome Logos | Cross-Site Request Forgery (CSRF) to SQL Injection (SQLi) |
Bitcoin / AltCoin Payment Gateway for WooCommerce | SQL Injection (SQLi) |
bizcalendar-web | SQL Injection (SQLi) |
Cart tracking for WooCommerce | SQL Injection (SQLi) |
Church Admin | SQL Injection (SQLi) |
Code Clone | SQL Injection (SQLi) from snippetId Parameter |
WordPress CURCY - WooCommerce Multi Currency - Currency Switcher | Unauthenticated SQL Injection (SQLi) |
Duplicate Page and Post | SQL Injection (SQLi) |
Eventer | SQL Injection (SQLi) from reg_id |
EZ SQL Reports Shortcode Widget and DB Backup | Cross-Site Request Forgery (CSRF) to SQL Injection (SQLi) |
FlexStock | SQL Injection (SQLi) |
Flickr set slideshows | SQL Injection (SQLi) |
Flickr set slideshows | SQL Injection (SQLi) |
WordPress Hero Maps Premium - Customizable Google Maps Plugin | SQL Injection (SQLi) |
Hero Slider | SQL Injection (SQLi) |
JiangQie Official Website Mini Program | SQL Injection (SQLi) |
JS Help Desk | SQL Injection (SQLi) |
Lead Form Data Collection to CRM | SQL Injection (SQLi) |
MC Woocommerce Wishlist | SQL Injection (SQLi) |
Multiple Shipping And Billing Address For Woocommerce | SQL Injection (SQLi) |
Navigation Tree Elementor | SQL Injection (SQLi) |
Newsletters | SQL Injection (SQLi) |
Pods | SQL Injection (SQLi) |
PostMash | SQL Injection (SQLi) |
Post SMTP | SQL Injection (SQLi) from columns Parameter |
Product Catalog | SQL Injection (SQLi) |
Product Labels For Woocommerce | SQL Injection (SQLi) |
Product Labels For Woocommerce | SQL Injection (SQLi) |
ProfileGrid | SQL Injection (SQLi) |
PublishPress Authors | SQL Injection (SQLi) |
ReportAttacks | SQL Injection (SQLi) |
Schedule | SQL Injection (SQLi) |
School Management | SQL Injection (SQLi) from 'view-attendance' |
School Management | SQL Injection (SQLi) from 'mj_smgt_show_event_task' |
SEO Plugin by Squirrly SEO | SQL Injection (SQLi) |
SEO Plugin by Squirrly SEO | SQL Injection (SQLi) from search Parameter |
Shuffle | SQL Injection (SQLi) |
Simple Giveaways | SQL Injection (SQLi) |
Slider by BestWebSoft | SQL Injection (SQLi) |
SMS Alert Order Notifications – WooCommerce | SQL Injection (SQLi) |
STEdb Forms | SQL Injection (SQLi) |
Super Simple Subscriptions | SQL Injection (SQLi) |
teachPress | SQL Injection (SQLi) |
Thumbnail carousel slider | SQL Injection (SQLi) |
Traveler Theme | SQL Injection (SQLi) |
Trust Payments Gateway for WooCommerce | SQL Injection (SQLi) |
Ultimate Member | Unauthenticated SQL Injection (SQLi) from search Parameter |
Vimeotheque | SQL Injection (SQLi) |
Web Directory Free | SQL Injection (SQLi) |
WooCommerce Multivendor Marketplace – REST API | SQL Injection (SQLi) |
WooMail | Missing Authorization (BAC) to SQL Injection (SQLi) |
WordPress Awesome Import & Export Plugin - Import & Export WordPress Data | Missing Authorization (BAC) to SQL Execution (SQLi) and Privilege Escalation (BAC) |
WPCOM Member | Unauthenticated Time-Based SQL Injection (SQLi) |
WP Featured Entries | SQL Injection (SQLi) |
WP Google Calendar Manager | SQL Injection (SQLi) |
WP Google Review Slider | Cross-Site Request Forgery (CSRF) to SQL Injection (SQLi) |
WPGuppy | SQL Injection (SQLi) |
WP Multistore Locator | SQL Injection (SQLi) |
WP Profitshare | SQL Injection (SQLi) |
WP-Recall | SQL Injection (SQLi) |
WPSchoolPress | Parent's account SQL Injection (SQLi) |
WPSchoolPress | Teacher's account SQL Injection (SQLi) |
WP Subscription Forms | SQL Injection (SQLi) |
دکمه، شبکه اجتماعی خرید | SQL Injection (SQLi) |
WordPress SQL Injections (SQLi) reported in 2023: | 223 |
WordPress SQL Injections (SQLi) reported in 2024: | 385 |
WordPress SQL Injections (SQLi) reported in 2025: | 262 |
MANAGED WP/Woo Security: WP SQL Injections Related Posts
Table of Contents
- WP SQLi APR 2025 | WP SQL Injections
- Managed WP/Woo Security Report
- Hire security professionals to protect your WordPress / WooCommerce: BEFORE IT’S TOO LATE! You will also protect your customers, your reputation and your online business!
- Get Healthy, Stay Healthy! A healthier online business starts today and it begins with you. Hire security experts to solve all your WP SQL Injections issues.
- Get security LIVEPATCH
- Stay informed
- Not sure that our recurrent security offer is worthy of long-term consideration? Contact us today for an WP SQL Injections audit! Decide after you compare RISK + IMPACT versus COST.
- MANAGED WP/Woo Security: WP SQL Injections Related Posts
- WP SQLi MAR 2025: 53 WP SQL Injections 2025 Hack
- WP SQLi FEB 2025: 73 WP SQL Injections 2025 Hack
- WP SQLi JAN 2025: 67 WP SQL Injections 2025 Hack
- WP SQLi DEC 2024: 26 WP SQL Injections 2024 Hack