SQL Injection Vulnerability in WordPress Plugin Store by Mike Rooijackers
CVE-2020-25379
8.8HIGH
What is CVE-2020-25379?
The WordPress Plugin Store, specifically version 0.8 developed by Mike Rooijackers, contains a security flaw where the 'Manufacturer[]' parameter does not properly sanitize user input. This oversight allows an authenticated attacker to craft and inject malicious SQL queries into the database. If exploited, this vulnerability can lead to unauthorized access to sensitive data or potential manipulation of the database, highlighting the importance of securing input parameters in web applications.