CVE-2025-58789
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-05

Last updated on: 2026-04-23

Assigner: Patchstack

Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle WP Full Stripe Free wp-full-stripe-free allows SQL Injection.This issue affects WP Full Stripe Free: from n/a through <= 8.2.5.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-05
Last Modified
2026-04-23
Generated
2026-06-16
AI Q&A
2025-09-05
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
themeisle wp_full_stripe_free *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2025-58789 is an SQL Injection vulnerability in the WordPress WP Full Stripe Free Plugin (up to version 8.3.0). It allows a malicious actor with administrator privileges to manipulate the website's database by injecting malicious SQL commands. This can lead to unauthorized data access or manipulation. The vulnerability falls under the OWASP Top 10 category A3: Injection and has a moderate severity CVSS score of 7.6. [1]

Impact Analysis

If exploited, this vulnerability can allow an attacker with administrator access to steal or manipulate data in the website's database. This could lead to data breaches or unauthorized changes to sensitive information. However, exploitation requires administrator-level access, and the impact is considered moderate. There is currently no official patch, but virtual patching is available as a mitigation. [1]

Detection Guidance

Detection of this vulnerability involves monitoring for suspicious administrator-level activities interacting with the database, as exploitation requires admin privileges. Since no specific detection commands are provided, general SQL injection detection methods such as monitoring web application logs for unusual SQL queries or using web application firewalls with SQL injection detection rules are recommended. Additionally, monitoring for unexpected database queries or changes initiated by admin users may help identify exploitation attempts. [1]

Mitigation Strategies

Immediate mitigation steps include applying virtual patching (vPatching) offered by Patchstack, which provides rapid protection without performance loss even in the absence of an official fix. Users should monitor for official updates or patches, restrict administrator access to trusted personnel only, and consider professional incident response if compromise is suspected. [1]

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-58789. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart