WordPress Plugin Vulnerabilities

WPML String Translation < 3.2.6 - Admin+ SQLi

Description

The context parameter on the String Translation admin page is passed directly into SQL queries without being properly sanitized, allowing SQL injection.

Proof of Concept

Affects Plugins

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Original Researcher
Stephen
Submitter
Stephen
Verified
Yes

Timeline

Publicly Published
2023-07-24 (about 2 years ago)
Added
2023-07-24 (about 2 years ago)
Last Updated
2023-08-01 (about 2 years ago)

Other