Skip to content

Known CVE

WordPress CBX Bookmark & Favorite Plugin <= 2.0.4 - SQL Injection

CBX Bookmark & Favorite WordPress plugin <= 2.0.4 contains a SQL injection caused by insufficient escaping of the 'orderby' parameter, letting authenticated attackers with Subscriber-level access extract sensitive database information

CVE-2025-13652

Critical2025CVSS 9.1CWE-89

cve2025 · wp-plugin · sqli · wordpress · cbxwpbookmark · authenticated · wp

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website