WordPress Plugin Vulnerabilities

Multiple Page Generator < 3.3.18 - SQLi via CSRF

Description

The plugin does not have CSRF check in the projects_list function, and does not escape the orderly & order parameters before using them in a SQL statement, which could allow attackers to make logged in administrators perform SQL Injection and lead to DoS via a CSRF attack

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Marco Wotschka
Verified
No

Timeline

Publicly Published
2023-05-16 (about 3 years ago)
Added
2023-05-17 (about 3 years ago)
Last Updated
2023-05-17 (about 3 years ago)

Other