References https://nvd.nist.gov/vuln/detail/CVE-2025-4172 https://wpscan.com/vulnerability/f5ab97cb-7825-4004-bef3-37764844664c/ https://avd.aquasec.com/nvd/2025/cve-2025-4172/ https://cve.imfht.com/detail/CVE-2025-4172 https://www.wordfence.com/blog/2025/05/wordfence-intelligence-weekly-wordpress-vulnerability-report-april-28-2025-to-may-4-2025/ https://hackhalt.com/threat/cve-2025-4172/ https://vuldb.com/sv/?id.307191 https://solidwp.com/blog/wordpress-vulnerability-report-may-7-2025/
Related VulnerabilitiesPoCCVE-2026-16268: Newsletters < 4.16 - Unauthenticated SSRF via SNS Bounce HandlerPoCCVE-2026-52774: YesWiki Bazar Widget - Reflected XSS via 'id' ParameterPoCCVE-2026-3018: WordPress Newsletters <= 4.13 - Unauthenticated SQL InjectionPoCCVE-2025-14726: WordPress Widgets for Social Photo Feed <= 1.8 - Information DisclosurePoCCVE-2024-30464: WPZOOM Social Icons Widget <= 4.2.15 - Missing AuthorizationPoCCVE-2022-0439: Email Subscribers & Newsletters <= 5.3.1 - Authenticated SQL InjectionPoCCVE-2022-44588: Cryptocurrency Widgets Pack <= 1.8.1 - SQL InjectionPoCCVE-2024-13098: WordPress Email Newsletter - Reflected XSSPoCCVE-2024-13099: Widget4Call WordPress - Cross-Site ScriptingPoCwp-newsletter-fpd: WordPress Plugin Newsletter - Full Path DisclosurePoCwp-widget-logic-fpd: WordPress Widget Logic - Full Path DisclosurePoCwp-newsletter-log-exposure: WordPress Newsletter - Log File ExposurePoCwp-image-widget-fpd: Image Widget - Full Path Disclosure