WordPress Plugin Vulnerabilities

Recall Products <= 0.8 - Authenticated SQL Injection

Description

The `Manufacturer[]` POST parameter is vulnerable to SQL injection when submitting a deletion request.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Original Researcher
ZeroAptitude
Verified
No

Timeline

Publicly Published
2020-08-31 (about 5 years ago)
Added
2020-08-31 (about 5 years ago)
Last Updated
2020-09-16 (about 5 years ago)

Other