WordPress Plugin Vulnerabilities

WP User Frontend < 3.5.25 - Admin+ SQL Injection

Description

The plugin does not validate and escape the post_id parameter from the Subscribers list before using in a SQL statement, leading to an SQL injection

Proof of Concept

Affects Plugins

Fixed in 3.5.25

References

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Verified
Yes

Timeline

Publicly Published
2021-11-18 (about 4 years ago)
Added
2021-11-18 (about 4 years ago)
Last Updated
2021-11-18 (about 4 years ago)

Other