SQL Injection Vulnerability in BulletProof Security Plugin for WordPress
CVE-2014-7959
Currently unrated
Summary
The BulletProof Security plugin for WordPress suffers from an SQL injection vulnerability that allows authenticated remote users to execute arbitrary SQL commands through the 'tableprefix' parameter in the admin/htaccess/bpsunlock.php script. This security flaw could potentially lead to unauthorized access and manipulation of the database, making it crucial for users to update to version 0.51.1 or later to safeguard their installations.
References
Timeline
Vulnerability published
Vulnerability Reserved