Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a request to save the settings.

CWE 1 Total

  • CWE-89 SQL Injection

Product Status

Learn more

Versions 1 Total

Default Status: unaffected

affected

Credits

  • Nguyen Van Khanh - SunCSR (Sun* Cyber Security Research) finder
  • WPScan coordinator

Updated:

This container includes required additional information provided by the CVE Program for this vulnerability.

References 1 Total