Description
SQL injection vulnerability in zp-core/zp-extensions/wordpress_import.php in Zenphoto before 1.4.5.4 allows remote authenticated administrators to execute arbitrary SQL commands via the tableprefix parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin BP Profile Search PHP Object Injection (4.5.3)
WordPress Plugin Chamber Dashboard Business Directory Cross-Site Scripting (3.2.8)
phpBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-7143)
PHP-Fusion Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-3172)