WordPress Plugin Vulnerabilities

User Control - Unauthenticated SQL Injection

Description

The User Control plugin has a vulnerability that allows every (unauthenticated) website visitor to perform arbitrary SQL queries.

Affects Plugins

No known fix

References

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Submitter
JustThomas
Submitter website
Verified
No

Timeline

Publicly Published
2018-01-28 (about 8 years ago)
Added
2018-01-29 (about 8 years ago)
Last Updated
2019-11-01 (about 6 years ago)

Other