WordPress Plugin Vulnerabilities

My wpdb < 2.5 - Arbitrary SQL Query via CSRF

Description

The plugin is missing CSRF check when running SQL queries, which could allow attacker to make a logged in admin run arbitrary SQL query via a CSRF attack

Proof of Concept

Affects Plugins

Fixed in 2.5

References

Classification

Miscellaneous

Original Researcher
Daniel Ruf
Submitter
Daniel Ruf
Submitter website
Verified
Yes

Timeline

Publicly Published
2022-10-28 (about 3 years ago)
Added
2022-10-28 (about 3 years ago)
Last Updated
2022-10-28 (about 3 years ago)

Other