SQL Injection Vulnerability in Wti-like-post Plugin for WordPress
CVE-2015-9466
9.8CRITICAL
What is CVE-2015-9466?
The Wti-like-post plugin for WordPress, prior to version 1.4.3, is vulnerable to SQL injection attacks. An attacker can exploit this vulnerability through manipulated HTTP headers, such as HTTP_CLIENT_IP or HTTP_X_FORWARDED_FOR. This can allow unauthorized access to sensitive data within the WordPress database. Website administrators are advised to update to the latest version to mitigate this security risk.