CVE-2025-14353Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.0.2 via the 'zipcode' parameter. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-03-07); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-07: 4Mentions · 2026-03-12: 1Technical Details · 2026-03-07: 3Technical Details · 2026-03-12: 103-0703-12
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-074
Disclosure3General1
2026-03-121
Disclosure1
Full discourse5 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-14353 (CVSS:7.5, HIGH) is Awaiting Analysis. The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in all versions up to, and inc..https://nvd.nist.gov/vuln/detail/CVE-2025-14353 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2025-14353, a high‑severity SQL injection flaw in the WordPress ZIP Code Based Content Protection plugin, and notes it is still awaiting analysis. No PoC, exploit, or patch is discussed.

    0000045
    172 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-14353 The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.0.2 via the 'zipcode' parameter. Thi… https://www.cve.org/CVERecord?id=CVE-2025-14353 ----- Traducción: CVE-2025-14353 El … http://infoflow.cloud`

    Post summary

    The tweet highlights CVE‑2025‑14353 as an SQL injection vulnerability in the ZIP Code Based Content Protection plugin for WordPress, providing technical details but no evidence of a PoC, exploit, patch, or active exploitation.

    00000173
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-14353 The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.0.2 via the 'zipcode' parameter. Thi… https://www.cve.org/CVERecord?id=CVE-2025-14353

    Post summary

    The CVE-2025-14353 vulnerability is an unauthenticated SQL injection in the ZIP Code Based Content Protection WordPress plugin (versions up to 1.0.2) via the 'zipcode' parameter, with no reported exploitation, PoC, or patch details.

    00000245
    56.6K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2025-14353 - presstigers - ZIP Code Based Content Protection - https://www.redpacketsecurity.com/cve-alert-cve-2025-14353-presstigers-zip-code-based-content-protection/ #OSINT #ThreatIntel #CyberSecurity #cve-2025-14353 #presstigers #zip-code-based-content-protection

    Post summary

    The tweet announces a CVE alert for CVE-2025-14353 and directs readers to a link for more information, but provides no additional technical or exploit details.

    00000231
    3.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-14353 SQL Injection in WordPress ZIP Code Based Content Protection Plugin <= 1.0.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-14353

    Post summary

    The post announces a SQL injection vulnerability in the WordPress ZIP Code Based Content Protection Plugin (<=1.0.2) but does not provide evidence of exploitation, patches, or a PoC.

    00000116
    4.0K followersView on X

Explore more