Description
WordPress Plugin Query Interface is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently manipulate SQL queries by executing arbitrary SQL code. WordPress Plugin Query Interface version 1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2 or latest
References
Related Vulnerabilities
WordPress 4.1.x Multiple Vulnerabilities (4.1 - 4.1.18)
WordPress Plugin GiveWP-Donation and Fundraising Platform Cross-Site Scripting (2.23.2)
WordPress Plugin WP Maintenance Mode Remote Code Execution (2.0.6)
WordPress Plugin Appointment Booking Calendar Multiple Vulnerabilities (1.1.24)
XWiki Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2022-41932)