WordPress Plugin Vulnerabilities

Link-Library <= 5.9.13.26 – Authenticated SQL Injection

Description

Type user access: admin user.

$_GET[‘linkid’] is not escaped.

Proof of Concept

Affects Plugins

Fixed in 5.9.13.27

References

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Submitter
Lenon Leite / Log.pt
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2017-08-14 (about 8 years ago)
Added
2017-08-16 (about 8 years ago)
Last Updated
2019-11-01 (about 6 years ago)

Other