The File Provider WordPress plugin through 1.2.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
CVE ID: CVE-2025-4578
Vendor: Unknown
Product: File Provider
EPSS Score: 0.12% (probability of being exploited)
EPSS Percentile: 31.37% (scored less or equal to compared to others)
EPSS Date: 2025-06-05 (when was this score calculated)