SQL Injection Vulnerabilities in All In One WP Security & Firewall Plugin for WordPress
CVE-2014-6242

Currently unrated

What is CVE-2014-6242?

The All In One WP Security & Firewall plugin for WordPress has multiple SQL injection vulnerabilities that allow remote authenticated users to execute arbitrary SQL commands. Specifically, these vulnerabilities can be exploited via the 'orderby' or 'order' parameters on the aiowpsec page, accessed through wp-admin/admin.php. This weakness may also be exploited using Cross-Site Request Forgery (CSRF) techniques, enabling attackers to execute malicious SQL commands without direct interaction.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.