WordPress Plugin Vulnerabilities

Ultimate Product Catalogue <= 4.2.2 - Authenticated SQL Injection

Description

Type user access: subscriber upwards.

$_POST[‘CatID’] is not escaped.

File / Code:

Path: /wp-content/plugins/ultimate-product-catalogue/Functions/Process_Ajax.php

Proof of Concept

Affects Plugins

References

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Submitter
Lenon Leite / Log.pt
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2017-06-27 (about 8 years ago)
Added
2017-06-28 (about 8 years ago)
Last Updated
2019-11-01 (about 6 years ago)

Other