Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jwg6-9jwg-258q

Опубликовано: 05 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

EPSS

Процентиль: 26%
0.00092
Низкий

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
nvd
около 1 месяца назад

The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

EPSS

Процентиль: 26%
0.00092
Низкий

8.6 High

CVSS3