PatchSiren cyber security CVE debrief
CVE-2025-23993 RiceTheme CVE debrief
A critical SQL injection vulnerability exists in the Felan Framework plugin, affecting versions up to and including 1.1.3. This issue allows attackers to inject malicious SQL code, potentially leading to unauthorized data access or modification. The vulnerability has a CVSS score of 9.3 and is considered critical. Defenders and security teams responsible for WordPress installations with the Felan Framework plugin should assess exposure and prioritize remediation to prevent potential unauthorized data access or modification. The CVE record and NVD entry provide details on the vulnerability.
- Vendor
- RiceTheme
- Product
- Felan Framework
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-08
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-08
- Advisory updated
- 2026-09-30
Who should care
Defenders and security teams responsible for WordPress installations with the Felan Framework plugin should assess exposure and prioritize remediation.
Why it matters
A critical SQL injection vulnerability exists in the Felan Framework plugin, affecting versions up to and including 1.1.3. Defenders should assess exposure and prioritize remediation to prevent potential unauthorized data access or modification.
- Potential unauthorized data access or modification due to SQL injection
- Need for defenders to assess exposure and apply patches or mitigations
- Potential for attackers to exploit this vulnerability in affected systems
Technical summary
The Felan Framework plugin is vulnerable to SQL injection, allowing attackers to inject malicious SQL code. The issue affects versions up to and including 1.1.3 and has a CVSS score of 9.3. This vulnerability is considered critical and has significant operational impacts, including potential unauthorized data access or modification. Defenders should assess exposure and apply patches or mitigations to vulnerable instances. The vulnerability is described as a SQL injection issue in the Felan Framework plugin.
Defensive priority
High priority for defenders to assess exposure and apply patches or mitigations.
Recommended defensive actions
- Assess exposure of Felan Framework plugin versions up to and including 1.1.3
- Apply patches or mitigations to vulnerable instances
- Monitor for potential SQL injection attacks
- Verify inventory of affected systems and prioritize remediation
Evidence notes
The vulnerability is described as a SQL injection issue in the Felan Framework plugin, with a CVSS score of 9.3 and a severity of CRITICAL. The CVE record and NVD entry provide details on the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-23993 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-23993
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-23993 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-23993
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.