CVE-2025-69310
Published: 20 February 2026
Summary
CVE-2025-69310 is a critical-severity SQL Injection (CWE-89) vulnerability. Its CVSS base score is 9.3 (Critical).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 19.9th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-2 (Flaw Remediation).
Deeper analysis
CVE-2025-69310 is an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that enables Blind SQL Injection in the TeconceTheme Woodly Core WordPress plugin (woodly-core). This flaw affects all versions of Woodly Core from an unspecified initial release through 1.4 inclusive.
The vulnerability carries a CVSS v3.1 base score of 9.3 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L), indicating that unauthenticated remote attackers require only low complexity and no user interaction to exploit it over the network. Exploitation allows attackers to achieve high confidentiality impact by extracting sensitive data from the underlying database through blind SQL injection techniques, alongside a low availability impact.
The Patchstack advisory at https://patchstack.com/database/Wordpress/Plugin/woodly-core/vulnerability/wordpress-woodly-core-plugin-1-4-sql-injection-vulnerability?_s_id=cve documents this SQL injection vulnerability in the Woodly Core WordPress plugin version 1.4 and provides associated mitigation guidance.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-207947
Vulnerability details
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Woodly Core woodly-core allows Blind SQL Injection.This issue affects Woodly Core: from n/a through <= 1.4.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Direct remote unauthenticated exploitation of public-facing WordPress plugin via SQL injection for data access.
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Directly remediates the SQL injection flaw in Woodly Core plugin versions through 1.4 by identifying, reporting, and applying patches.
Enforces information input validation at entry points to neutralize special elements in SQL commands, preventing blind SQL injection exploitation.
Boundary protection using web application firewalls monitors and blocks malicious SQL injection payloads targeting the vulnerable plugin.