CVE-2025-22536Active Exploitation

LOWCVSS 7.6 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hiren.sabd WP Music Player wp-music-player allows SQL Injection.This issue affects WP Music Player: from n/a through <= 1.3.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-04-16); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-16: 1Mentions · 2026-04-17: 1Active Exploitation · 2026-04-16: 1Active Exploitation · 2026-04-17: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-17: 104-1604-17
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • Security Arsenal, LLC@SecurityAr58409
    Active Exploitation

    🔒 #CyberSecurity CVE-2025-22536 (React2Shell): Automated Credential Harvesting in Next.js Apps —… "The security community is currently tracking an active threat cluster,…" 🔗 https://securityarsenal.com/blog/cve-2025-22536-react2shell-automated-credential-harvesting-in-nextjs-apps-detection-and-remediation #CyberSecurity #ThreatIntel #penetrationtesting #redteam #offensivesecurity

    Post summary

    CVE-2025-22536 (React2Shell) is currently being tracked as an active threat cluster targeting Next.js applications with automated credential harvesting; no PoC, exploit tool, or patch information is provided.

    00000516
    10 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Active Exploitation

    🔒 #CyberSecurity CVE-2025-22536 (React2Shell): Automated Credential Harvesting in Next.js Apps —… "Active exploitation of vulnerable Next.js apps via CVE-2025-22536…" 🔗 https://securityarsenal.com/blog/cve-2025-22536-react2shell-automated-credential-harvesting-in-nextjs-apps-detection-and-remediation #CyberSecurity #ThreatIntel #penetrationtesting #redteam #offensivesecurity

    Post summary

    The message highlights that CVE-2025-22536 (React2Shell) is being actively exploited in the wild against Next.js applications, with a linked blog offering detection and remediation guidance.

    00000340
    10 followersView on X

Explore more