SQL Injection Vulnerability in Mail Masta Plugin for WordPress
CVE-2017-6570
7.2HIGH
What is CVE-2017-6570?
The Mail Masta plugin for WordPress, specifically version 1.0, contains a SQL injection vulnerability that can be exploited by individuals with administrative access. This flaw resides in the file ./inc/campaign/view-campaign-list.php and can be triggered through the GET parameter 'id'. Successful exploitation may allow attackers to manipulate the underlying database, potentially leading to unauthorized data exposure or modification. Site administrators are encouraged to secure their installations and consider updating to address this issue.