CVE advisoryCRITICAL
CVE-2025-10738
WordPress URL Shortener Plugin SQL Injection
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A critical SQL injection vulnerability exists in a WordPress plugin that shortens URLs, allowing unauthenticated attackers to extract sensitive database information by manipulating a parameter. This issue is reachable via the internet as part of the plugin's normal function, posing a risk to data confidentiality.