SQL Injection Vulnerability in Gift Vouchers Plugin for WordPress
CVE-2018-16159
Key Information:
- Vendor
Wordpress
- Status
- Vendor
- CVE Published:
- 30 August 2018
Badges
What is CVE-2018-16159?
The Gift Vouchers plugin, utilized by numerous WordPress sites, contains a vulnerability that allows an attacker to execute SQL injection attacks through the template_id parameter when making a request to wp-admin/admin-ajax.php with the wpgv_doajax_front_template action. This could lead to unauthorized access to sensitive data within the database, potentially compromising the integrity and confidentiality of user information and website operations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
65% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved