WordPress Plugin Vulnerabilities

Content Timeline <= 4.4.2 - Multiple Blind SQL Injection

Description

Multiple Blind SQL injections in the premium 'Content Timeline' Plugin. One unauthenticated and two authenticated injections.

Contacted the author twice without any response.

## History:

09-16-2017 Contacted the author
09-16-2017 Requested CVE-ID
09-18-2017 CVE-ID Received
09-18-2017 Contacted the author again
09-26-2017 No reaction from author, thus releasing.

Proof of Concept

Affects Plugins

Fixed in 4.4.3

References

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Submitter
Jeroen - IT Nerdbox
Submitter twitter
Verified
No

Timeline

Publicly Published
2017-09-26 (about 8 years ago)
Added
2017-10-03 (about 8 years ago)
Last Updated
2020-09-22 (about 5 years ago)

Other