---
id: CVE-2025-14477
title: >-
  The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all
  versions up to, and including, 3.1.0 due to insufficient escaping on the user
  supplied parameter and lack of sufficient preparation on the existing SQL
  query
summary: >-
  The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all
  versions up to, and including, 3.1.0 due to insufficient escaping on the user
  supplied parameter and lack of sufficient preparation on the existing SQL
  query. Th…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-89
published: '2025-12-13'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14477'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/404-solution/tags/2.36.10/includes/DataAccess.php#L977
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/404-solution/tags/2.36.10/includes/DataAccess.php#L987
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/404-solution/tags/2.36.10/includes/PluginLogic.php#L1595
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/404-solution/tags/2.36.10/includes/sql/getRedirectsForView.sql#L106
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3417333%40404-solution&new=3417333%40404-solution&sfp_email=&sfph_mail=
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/389bee79-b59f-484a-86df-f041d6b00051?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00359
epssPercentile: 0.27477
ingestedAt: '2026-10-07T20:46:46.934Z'
---

## Overview

The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This is due to improper sanitization of the `filterText` parameter in the `ajaxUpdatePaginationLinks` AJAX action. The sanitization logic can be bypassed by using the sequence `*$/` which becomes `*/` after the `$` character is removed, allowing attackers to escape SQL comment contexts. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database via a time-based blind SQL injection technique.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
