CBX Bookmark & Favorite WordPress plugin <= 2.0.4 contains a SQL injection caused by insufficient escaping of the 'orderby' parameter, letting authenticated attackers with Subscriber-level access extract sensitive database information
id: CVE-2025-13652
info:
name: WordPress CBX Bookmark & Favorite Plugin <= 2.0.4 - SQL Injection
...