Known CVE
WordPress CBX Bookmark & Favorite Plugin <= 2.0.4 - SQL Injection
CBX Bookmark & Favorite WordPress plugin <= 2.0.4 contains a SQL injection caused by insufficient escaping of the 'orderby' parameter, letting authenticated attackers with Subscriber-level access extract sensitive database information
CVE-2025-13652
Critical2025CVSS 9.1CWE-89
cve2025 · wp-plugin · sqli · wordpress · cbxwpbookmark · authenticated · wp
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website