CVE-2025-13000: JIMBOB1953 DB-Access

High severity, CVSS 7.7. EPSS: 0.3% chance of exploitation in the next 30 days.

The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated users, such as subscriber to perform SQLI attacks

Affected products

Published 2025-12-02. Last modified 2026-06-17.