SQL Injection Vulnerability in Podlove Podcast Publisher Plugin for WordPress
CVE-2017-12949
8.8HIGH
What is CVE-2017-12949?
A security flaw exists within the Podlove Podcast Publisher plugin, specifically in the orderby parameter of the contributor_list_table.php file. This vulnerability allows for SQL injection through the wp-admin/admin.php interface, which can be exploited via Cross-Site Request Forgery (CSRF) attacks. Malicious actors may leverage this flaw to manipulate database queries and obtain unauthorized access to sensitive information, posing significant risks to WordPress installations utilizing this plugin.