PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-23993 RiceTheme CVE debrief

A critical SQL injection vulnerability exists in the Felan Framework plugin, affecting versions up to and including 1.1.3. This issue allows attackers to inject malicious SQL code, potentially leading to unauthorized data access or modification. The vulnerability has a CVSS score of 9.3 and is considered critical. Defenders and security teams responsible for WordPress installations with the Felan Framework plugin should assess exposure and prioritize remediation to prevent potential unauthorized data access or modification. The CVE record and NVD entry provide details on the vulnerability.

Vendor
RiceTheme
Product
Felan Framework
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-08
Original CVE updated
2026-09-30
Advisory published
2026-01-08
Advisory updated
2026-09-30

Who should care

Defenders and security teams responsible for WordPress installations with the Felan Framework plugin should assess exposure and prioritize remediation.

Why it matters

A critical SQL injection vulnerability exists in the Felan Framework plugin, affecting versions up to and including 1.1.3. Defenders should assess exposure and prioritize remediation to prevent potential unauthorized data access or modification.

  • Potential unauthorized data access or modification due to SQL injection
  • Need for defenders to assess exposure and apply patches or mitigations
  • Potential for attackers to exploit this vulnerability in affected systems

Technical summary

The Felan Framework plugin is vulnerable to SQL injection, allowing attackers to inject malicious SQL code. The issue affects versions up to and including 1.1.3 and has a CVSS score of 9.3. This vulnerability is considered critical and has significant operational impacts, including potential unauthorized data access or modification. Defenders should assess exposure and apply patches or mitigations to vulnerable instances. The vulnerability is described as a SQL injection issue in the Felan Framework plugin.

Defensive priority

High priority for defenders to assess exposure and apply patches or mitigations.

Recommended defensive actions

  • Assess exposure of Felan Framework plugin versions up to and including 1.1.3
  • Apply patches or mitigations to vulnerable instances
  • Monitor for potential SQL injection attacks
  • Verify inventory of affected systems and prioritize remediation

Evidence notes

The vulnerability is described as a SQL injection issue in the Felan Framework plugin, with a CVSS score of 9.3 and a severity of CRITICAL. The CVE record and NVD entry provide details on the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-23993 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-23993

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-23993 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-23993

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.