SQL Injection Vulnerabilities in All In One WP Security & Firewall Plugin for WordPress
CVE-2014-6242
Currently unrated
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 2 October 2014
Summary
The All In One WP Security & Firewall plugin for WordPress has multiple SQL injection vulnerabilities that allow remote authenticated users to execute arbitrary SQL commands. Specifically, these vulnerabilities can be exploited via the 'orderby' or 'order' parameters on the aiowpsec page, accessed through wp-admin/admin.php. This weakness may also be exploited using Cross-Site Request Forgery (CSRF) techniques, enabling attackers to execute malicious SQL commands without direct interaction.
References
EPSS Score
5% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved