SQL Injection Vulnerability in Cart66 Plugin for WordPress
CVE-2014-9305

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
8 December 2014

What is CVE-2014-9305?

An SQL injection vulnerability exists in the Cart66 Lite plugin for WordPress that allows remote authenticated users to execute arbitrary SQL commands. This weakness arises from improper validation in the shortcodeProductsTable function, specifically when processing the id parameter in a shortcode_products_table action. Attackers can exploit this flaw through wp-admin/admin-ajax.php, potentially gaining unauthorized access to sensitive database information.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.