- WordPress is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation. Successful exploits may result in unauthorized access. WordPress versions 2.0.6 and prior are vulnerable.
- Update to WordPress version 2.0.7 or latest
- WordPress Plugin MailChimp for WordPress Cross-Site Scripting (2.2.7)
- WordPress Plugin Contact Form DB CSV Injection (2.10.32)
- Drupal Core 6.x Remote Code Execution (6.0 - 6.38)
- WordPress Plugin MP3-jPlayer Multiple Cross-Site Scripting Vulnerabilities (1.8.7)
- WordPress Plugin Autoship Cloud PHP Object Injection (1.0.13)