- WordPress is prone to multiple SQL injection vulnerabilities because it fails to sufficiently sanitize user supplied data before using it in an SQL query. Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress versions prior to 3.1.4 are vulnerable.
- Update to WordPress version 3.1.4 or latest
- WordPress Plugin wp audio gallery playlist 'playlist.php' SQL Injection (0.12)
- WordPress Plugin Traffic Manager Multiple Vulnerabilities (1.4.5)
- WordPress Plugin WooCommerce Instamojo Cross-Site Scripting (0.0.6)
- WordPress Plugin AccessPress Anonymous Post Pro Arbitrary File Upload (3.1.9)
- WordPress Plugin Nmedia MailChimp Widget 'abs_path' Parameter Remote File Include (3.1)