WordPress Plugin Vulnerabilities

Post Grid < 2.1.13 - Contributor+ SQL Injection

Description

The plugin does not sanitise and escape user input before using it in a SQL statement when duplicating posts (available to Contributor+ users), leading to an SQL Injection

Affects Plugins

Fixed in 2.1.13

References

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Verified
Yes

Timeline

Publicly Published
2021-12-15 (about 4 years ago)
Added
2021-12-24 (about 4 years ago)
Last Updated
2021-12-24 (about 4 years ago)

Other