SQL Injection Vulnerability in WpJobBoard Plugin for WordPress
CVE-2018-5695

7.2HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
14 January 2018

Summary

The WpJobBoard plugin version 4.4.4 for WordPress contains a vulnerability that allows for SQL injection through improperly sanitized input parameters. Attackers can exploit this weakness by manipulating the 'order' or 'sort' arguments sent to the wpjb-job or wpjb-alerts module, particularly during requests to wp-admin/admin.php. This could lead to unauthorized access to sensitive data and potentially compromise the integrity of the WordPress site.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.