This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: Unauthenticated SQL Injection in WordPress plugin 'Course Booking System'.
๐ฅ **Consequences**: Attackers can extract sensitive database info. Data integrity & confidentiality are compromised.โฆ
๐ก๏ธ **CWE-89**: SQL Injection.
๐ **Root Cause**: Insufficient escaping of user-supplied parameters. Lack of prepared statements in SQL queries. Improper neutralization of special elements.
Q3Who is affected? (Versions/Components)
๐ฆ **Vendor**: ComMotion.
๐ **Affected**: 'Course Booking System' plugin.
๐ **Versions**: 6.0.5 and earlier. (Note: Some sources cite up to 6.0.6).
๐ **Platform**: WordPress sites using this specific plugin.
Q4What can hackers do? (Privileges/Data)
๐ต๏ธ **Attacker Action**: Append malicious SQL queries.
๐ **Data Access**: Extract sensitive data from the database (users, credentials, config).
๐ **Privileges**: Unauthenticated access required.โฆ
โก **Threshold**: LOW.
๐ **Auth**: None required (Unauthenticated).
๐ฑ๏ธ **UI**: No user interaction needed.
๐ **Network**: Remote exploitation possible (AV:N). Easy to exploit.
Q6Is there a public Exp? (PoC/Wild Exploitation)
โ **Yes, Public Exploits Exist**.
๐ **PoC**: Available on GitHub (RandomRobbieBF).
๐ **Scanner**: Nuclei templates available (projectdiscovery).
๐ฅ **Status**: Active exploitation potential is high due to easy access.
Q7How to self-check? (Features/Scanning)
๐ **Self-Check**: Scan for 'Course Booking System' plugin version.
๐ ๏ธ **Tools**: Use Nuclei templates for CVE-2025-22785.
๐ **Verify**: Check if version <= 6.0.5 (or 6.0.6).
๐ฉ **Flag**: Look for SQL injection errors in Hโฆ
๐ง **Fix**: Update plugin to latest version.
๐ข **Official**: Patch available from vendor/WordPress repo.
โ ๏ธ **Note**: Ensure version is strictly greater than 6.0.5/6.0.6.
๐ **Action**: Immediate update recommended.
Q9What if no patch? (Workaround)
๐ซ **No Patch?**: Disable the plugin immediately.
๐ก๏ธ **WAF**: Deploy Web Application Firewall rules to block SQLi patterns.
๐ **Access Control**: Restrict access to plugin endpoints if possible.
๐ **Risk**: High risk untiโฆ
๐ฅ **Priority**: CRITICAL.
โฑ๏ธ **Urgency**: HIGH.
๐ **CVSS**: High severity (C:H, S:C).
๐ **Action**: Patch NOW. Unauthenticated access makes this an immediate threat to any affected WordPress site.