Description
SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value in an XML RPC wp.suggestCategories methodCall, a different vector than CVE-2007-1897.
Remediation
References
Related Vulnerabilities
WordPress Plugin Velvet Blues Update URLs Unspecified Vulnerability (2.1)
WordPress Plugin Request a Quote Cross-Site Scripting (2.3.4)
WordPress Plugin Spiffy Calendar SQL Injection (4.9.11)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-4721)
WordPress Plugin Author Periodic Report Cross-Site Scripting (1.0)