← WordPress Vulnerabilities
WordPress security by component

WP Guppy

WP Guppy is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jun 09, 2025; the highest CVE/CNA score is 8.5.

Plugin slug: wp-guppy

CVE-2025-31920: WP Guppy: SQL injection

WP Guppy is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.

PublishedJun 09, 2025
Safe version guidanceSee mitigation notes
Safe version
Jun 09, 2025 CVE-2025-31920
WP Guppy: SQL injection
WP Guppy is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending
Dec 27, 2021 CVE-2021-24997
WP Guppy: Sensitive information exposure
WP Guppy is affected by sensitive information exposure. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE6.5
NVD6.5