Description
WordPress Plugin Query Interface is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently manipulate SQL queries by executing arbitrary SQL code. WordPress Plugin Query Interface version 1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2 or latest
References
Related Vulnerabilities
WordPress 2.1.1 Cross-Site Scripting Vulnerability (2.1.1 - 2.1.1)
WordPress Plugin Minimal Coming Soon & Maintenance Mode-Coming Soon Page Security Bypass (2.15)
WordPress Plugin WP Server Log Viewer Cross-Site Scripting (1.0)
WordPress 'cat' Parameter SQL Injection Vulnerability (1.5 - 1.5.1.1)
WordPress Plugin SAML SP Single Sign On-SSO login Cross-Site Scripting (4.8.72)