WordPress Plugin Vulnerabilities
WP Meta SEO < 4.5.3 - Subscriber+ SQLi
Description
The plugin does not properly sanitize and escape inputs into SQL queries, leading to a blind SQL Injection vulnerability that can be exploited by subscriber+ users.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
SQLI
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
dc11
Submitter
dc11
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2023-02-27 (about 2 years ago)
Added
2023-02-27 (about 2 years ago)
Last Updated
2023-02-27 (about 2 years ago)