SQL Injection Vulnerabilities in All In One WP Security & Firewall Plugin for WordPress
CVE-2014-6242
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 2 October 2014
Badges
What is CVE-2014-6242?
The All In One WP Security & Firewall plugin for WordPress has multiple SQL injection vulnerabilities that allow remote authenticated users to execute arbitrary SQL commands. Specifically, these vulnerabilities can be exploited via the 'orderby' or 'order' parameters on the aiowpsec page, accessed through wp-admin/admin.php. This weakness may also be exploited using Cross-Site Request Forgery (CSRF) techniques, enabling attackers to execute malicious SQL commands without direct interaction.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
5% chance of being exploited in the next 30 days.
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved