Skip to content

Add CVE-2025-1321 - WordPress teachPress SQL Injection#15879

Closed
neosmith1 wants to merge 1 commit intoprojectdiscovery:mainfrom
neosmith1:add-cve-2025-1321
Closed

Add CVE-2025-1321 - WordPress teachPress SQL Injection#15879
neosmith1 wants to merge 1 commit intoprojectdiscovery:mainfrom
neosmith1:add-cve-2025-1321

Conversation

@neosmith1
Copy link
Copy Markdown
Contributor

Template Details

  • CVE: CVE-2025-1321
  • Product: teachPress WordPress Plugin
  • Vulnerability: Unauthenticated SQL Injection
  • Severity: Medium (7.5 CVSS)
  • Detection: ORDER BY clause injection via tpsearch shortcode parameter

References

@github-actions github-actions bot requested a review from DhiyaneshGeek April 10, 2026 14:45
@theamanrawat theamanrawat added the Done Ready to merge label Apr 13, 2026
@theamanrawat
Copy link
Copy Markdown
Contributor

Hi @neosmith1,

Thank you so much for sharing this template with the community and for contributing to this project. After review, it appears the CVE is authenticated, but the PoC in the template is unauthenticated. For this reason, we are closing this PR for now. Please feel free to submit the template with the updated PoC.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Done Ready to merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants