Home/Research/CVEs/CVE-2025-9776 | SQL Injection in CatFolders Plugin

CVE-2025-9776 | SQL Injection in CatFolders Plugin

CVE-2025-9776: Authenticated SQL Injection via CSV Import in CatFolders WordPress plugin. CVSS 6.5. Full technical analysis and remediation by Kai Aizen.

TL;DR
This vulnerability has been assigned CVE-2025-9776 and is currently pending full publication details from the National Vulnerability Database (NVD). The vulnerability was discovered and responsibly disclosed by Kai Aizen (SnailSploit).
CVE Disclosures →

Status

This vulnerability has been assigned CVE-2025-9776 and is currently pending full publication details from the National Vulnerability Database (NVD). The vulnerability was discovered and responsibly disclosed by Kai Aizen (SnailSploit).

Description

Full technical details will be published once the vulnerability information is released by NVD and the affected software vendor has had adequate time to patch and notify users.

Timeline

  • Discovery: Vulnerability discovered during WordPress plugin security assessment
  • Disclosure: Responsibly disclosed to plugin developer
  • CVE Assignment: CVE-2025-9776 assigned
  • Status: Awaiting NVD publication

Updates

This page will be updated with complete technical details, proof of concept, and remediation guidance once the information is publicly available through NVD.

For the most current information, check the official NVD entry or contact [email protected].

References

Discovered by: Kai Aizen (SnailSploit)

cite this work
BibTeX
@misc{aizen2026cve,
  author = {Aizen, Kai},
  title  = {CVE-2025-9776 | SQL Injection in CatFolders Plugin},
  year   = {2026},
  url    = {https://snailsploit.com/security-research/cves/cve-2025-9776/},
  note   = {snailsploit.com}
}
APA

Aizen, K. (2026). CVE-2025-9776 | SQL Injection in CatFolders Plugin. snailsploit.com. https://snailsploit.com/security-research/cves/cve-2025-9776/

MLA

Aizen, Kai. "CVE-2025-9776 | SQL Injection in CatFolders Plugin." snailsploit, 2026, https://snailsploit.com/security-research/cves/cve-2025-9776/.

Chicago

Aizen, Kai. "CVE-2025-9776 | SQL Injection in CatFolders Plugin." snailsploit (blog). 2026. https://snailsploit.com/security-research/cves/cve-2025-9776/.

Permalink: https://snailsploit.com/security-research/cves/cve-2025-9776/
disclosure context
all disclosures
CVE Ledger →
23 published CVEs across container, web, OSS, kernel
advisories
GHSA disclosures →
coordinated security advisories
engage
Pen Testing →
same methodology, your stack
Author
Kai Aizen
Independent offensive security researcher. 23 published CVEs, 5 Linux kernel mainline patches, creator of AATMF / P.R.O.M.P.T / SEF, author of Adversarial Minds.