SQL Injection Vulnerability in Add Edit Delete Listing for Member Module Plugin by WordPress
CVE-2017-1002025

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
14 September 2017

What is CVE-2017-1002025?

A significant SQL injection vulnerability exists in the Add Edit Delete Listing for Member Module plugin version 1.0 for WordPress. The vulnerability arises from a lack of proper sanitization of user-supplied input before it is incorporated into SQL statements, which may allow attackers to manipulate database queries. This exploitation can lead to unauthorized access to sensitive data, potential database corruption, and other malicious activities. It is crucial for users of this plugin to implement appropriate patches or mitigating measures to secure their WordPress installations.

Affected Version(s)

add-edit-delete-listing-for-member-module < 1.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.