New Malware Targets Microsoft Windows Systems Without Using PE Header – Active IOCs
May 30, 2025DarkCrystal RAT aka DCRat – Active IOCs
May 30, 2025New Malware Targets Microsoft Windows Systems Without Using PE Header – Active IOCs
May 30, 2025DarkCrystal RAT aka DCRat – Active IOCs
May 30, 2025Severity
High
Analysis Summary
CVE-2025-5287 CVSS:7.5
The Likes and Dislikes Plugin plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versions up to, and including, 1.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2025-4800 CVSS:8.8
The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validation in the stm_lms_add_assignment_attachment function in all versions up to, and including, 4.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server, which may make remote code execution possible.
Impact
- Data Manipulation
- Gain Access
Indicators of Compromise
CVE
CVE-2025-5287
CVE-2025-4800
Affected Vendors
- WordPress
Affected Products
- erumfaham Likes and Dislikes Plugin - *
- StylemixThemes MasterStudy LMS Pro - *
Remediation
Update the WordPress plugin to the latest available version.