Описание
The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.2.0 (исключая)
cpe:2.3:a:updraftplus:wp-optimize:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 11%
0.00038
Низкий
4.1 Medium
CVSS3
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 4.1
github
8 месяцев назад
The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations.
EPSS
Процентиль: 11%
0.00038
Низкий
4.1 Medium
CVSS3
Дефекты
CWE-89