WordPress Plugin Vulnerabilities

Cost Calculator Builder < 3.2.29 - Admin+ SQL Injection

Description

The plugin does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.

Proof of Concept

Affects Plugins

References

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Submitter
Kientt
Verified
Yes

Timeline

Publicly Published
2024-09-09 (about 1 year ago)
Added
2024-09-09 (about 1 year ago)
Last Updated
2024-09-09 (about 1 year ago)

Other