Security Advisory
CVE-2025-28972
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) vulnerability in Suhas Surse WP Employee Attendance System wp-employee-attendance-system allows Blind SQL Injection.This issue affects WP Employee Attendance System: from n/a through <= 3.5.