Skip to content

Add CVE-2025-2221 - WordPress WPCOM Member SQL Injection#15878

Merged
theamanrawat merged 3 commits intoprojectdiscovery:mainfrom
neosmith1:add-cve-2025-2221
Apr 13, 2026
Merged

Add CVE-2025-2221 - WordPress WPCOM Member SQL Injection#15878
theamanrawat merged 3 commits intoprojectdiscovery:mainfrom
neosmith1:add-cve-2025-2221

Conversation

@neosmith1
Copy link
Copy Markdown
Contributor

Template Details

  • CVE: CVE-2025-2221
  • Product: WPCOM Member WordPress Plugin
  • Vulnerability: Unauthenticated SQL Injection
  • Severity: High (7.5 CVSS)
  • Detection: Time-based blind SQL injection via user_phone parameter

References

@neo-by-projectdiscovery-dev
Copy link
Copy Markdown
Contributor

neo-by-projectdiscovery-dev bot commented Apr 10, 2026

Neo - Nuclei Template Review

No security issues found

Hardening Notes
  • The template now properly extracts the nonce from wpcom_login_modal action before attempting SQL injection
  • Timeout directive (@timeout: 25s) appropriately accommodates the 6-second SLEEP payload with network latency buffer
  • Metadata improvements include proper vendor name (Bastien Ho), fofa-query, and unauthenticated tag

Comment @pdneo help for available commands. · Open in Neo

@Akokonunes
Copy link
Copy Markdown
Contributor

Hi @neosmith1

Thank you for contributing this template to the community! This appears to be AI-generated based on the template structure and testing claims. We tried to reproduce the PoC on a vulnerable target but were unable to confirm the behavior. If you believe the template is correct, please send details or a vulnerable lab environment to templates@projectdiscovery.io.

@Akokonunes Akokonunes closed this Apr 12, 2026
@Akokonunes Akokonunes added the Done Ready to merge label Apr 12, 2026
@Akokonunes Akokonunes reopened this Apr 13, 2026
@theamanrawat theamanrawat merged commit 71e59aa into projectdiscovery:main Apr 13, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Done Ready to merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants