WordPress Plugin Vulnerabilities
Slider by 10Web < 1.2.36 - Multiple Authenticated SQL Injection
Description
The bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin), or medium one such as Contributor+ (if "Role Options" is turn on for other users) to perform a SQL Injection attacks.
Proof of Concept
Affects Plugins
References
Classification
Type
SQLI
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Nguyen Anh Tien - SunCSR (Sun* Cyber Security Research)
Submitter
Nguyen Anh Tien
Submitter website
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2020-09-29 (about 5 years ago)
Added
2020-09-29 (about 5 years ago)
Last Updated
2021-01-21 (about 5 years ago)