SQL Injection Vulnerability in Podlove Podcast Publisher Plugin for WordPress
CVE-2017-12949
8.8HIGH
Summary
A security flaw exists within the Podlove Podcast Publisher plugin, specifically in the orderby parameter of the contributor_list_table.php file. This vulnerability allows for SQL injection through the wp-admin/admin.php interface, which can be exploited via Cross-Site Request Forgery (CSRF) attacks. Malicious actors may leverage this flaw to manipulate database queries and obtain unauthorized access to sensitive information, posing significant risks to WordPress installations utilizing this plugin.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability Reserved
Vulnerability published