Cyber Posture

CVE-2025-22537

High

Published: 09 January 2025

Published
09 January 2025
Modified
23 April 2026
KEV Added
Patch
CVSS Score 8.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
EPSS Score 0.0009 26.2th percentile
Risk Priority 17 60% EPSS · 20% KEV · 20% CVSS

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in traveller11 Google Maps Travel Route google-maps-travel-route allows SQL Injection.This issue affects Google Maps Travel Route: from n/a through <= 1.3.1.

Security Summary

CVE-2025-22537 is an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability, classified under CWE-89, in the Google Maps Travel Route WordPress plugin developed by traveller11. The vulnerability affects the plugin from unknown initial versions through 1.3.1.

The CVSS 3.1 base score is 8.5 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L), indicating network accessibility, low attack complexity, requirement for low privileges such as an authenticated WordPress user, no user interaction, and high scope. Exploitation enables a high confidentiality impact, allowing attackers to extract sensitive data from the database, with low integrity and availability impacts.

Mitigation details are available in the Patchstack advisory at https://patchstack.com/database/Wordpress/Plugin/google-maps-travel-route/vulnerability/wordpress-google-maps-travel-route-plugin-1-3-1-sql-injection-vulnerability?_s_id=cve.

Details

CWE(s)
CWE-89

References