S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Apr 13, 2026

CVE-2025-13652 Scanner

CVE-2025-13652 Scanner - SQL Injection vulnerability in WordPress CBX Bookmark & Favorite Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-13652
6.5
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.

The CBX Bookmark & Favorite plugin for WordPress is vulnerable to generic SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
CBX Bookmark & Favoriteby manchumahara
0
Updated Aug 19, 2026View on NVD →
Detail

The WordPress CBX Bookmark & Favorite Plugin is a recognized tool commonly used by WordPress website administrators to manage bookmarks and favorites. It is developed by Codeboxr and aims to enhance user experience by enabling easy bookmarking of pages on a WordPress site. Its primary users include bloggers, news websites, and sites with extensive user-generated content where bookmarking is beneficial. It facilitates seamless integration with WordPress ecosystems, offering flexibility and customization options to site owners. The plugin is vital for user interaction retention via bookmarks, which can be shared through social media or emails. It is an essential utility for WordPress sites focusing on personalized user experience.

The vulnerability associated with the WordPress CBX Bookmark & Favorite Plugin is a critical SQL Injection flaw. SQL Injection is a type of attack that exploits database query vulnerabilities by inserting malicious SQL code into input fields. The vulnerability arises from the improper escaping of the 'orderby' parameter, allowing potential attackers with low-level subscriber access to execute unauthorized actions on the database. If exploited successfully, this can lead to unauthorized access to sensitive data stored within the WordPress database. This attack vector poses significant risks, particularly in multi-user WordPress environments where data confidentiality is pivotal. Consequently, site administrators must address this vulnerability to maintain site security and protect user data.

From a technical standpoint, the vulnerable endpoint for this SQL Injection in the CBX Bookmark & Favorite Plugin is within an admin-ajax.php request. The vulnerability is located in the parameter 'orderby', which fails to properly escape or validate input. Attackers can manipulate this parameter to inject arbitrary SQL code, potentially allowing them to extract sensitive data or alter database contents. Specifically, the use of a subquery exploit in these parameters can delay responses, indicating successful execution. Detecting such a flaw entails capturing traffic for anomalies like unusually delayed responses upon sending crafted SQL Injection payloads. The vulnerability underscores the importance of ensuring parameterized queries and input validation in dynamic content management systems like WordPress.

Exploiting the SQL Injection vulnerability can lead to severe consequences. Attackers might extract confidential data such as user credentials, personal user data, and site configurations, which could be leveraged for further attacks. The integrity of the database might also be compromised, resulting in data being added, altered, or deleted without authorization. This could lead to data corruption or loss, potentially affecting site functionality and user trust. Furthermore, manipulated data could be used for reflecting misleading information to legitimate users or distributing malware. Overall, exploitation could significantly damage both data integrity and user confidence, emphasizing the need for immediate remediation.

REFERENCES

Solution Advice
  • Upgrade the CBX Bookmark & Favorite Plugin to a version later than 2.0.4 or the latest available version.
  • Implement input validation and sanitization processes for all user-input parameters.
  • Configure database accounts with the least privileges necessary for operation.
  • Enable monitoring and logging to detect and respond to anomalous database activity.
  • Educate users about the risks associated with low-level access accounts and enforce strong password policies.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.