Back

HIGH

CTL Behance Importer Lite <= 1.0 - Unauthenticated SQL Injection

Published Oct 2, 2025

Description

The CTL Behance Importer Lite WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (0)

No CWE recorded.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Oct 2, 2025
Updated Nov 13, 2025
Reserved Aug 28, 2025
CISA Vulnrichment
Updated Oct 2, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a