vendor:
Link Library plugin
by:
Miroslav Stampar
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Link Library plugin
Affected Version From: 5.2.2001
Affected Version To: 5.2.2001
Patch Exists: NO
Related CWE:
CPE: a:wordpress:link_library:5.2.1
Platforms Tested: WordPress
2011
WordPress Link Library plugin <= 5.2.1 SQL Injection Vulnerability
The WordPress Link Library plugin version 5.2.1 is vulnerable to SQL Injection. An attacker can exploit this vulnerability to execute arbitrary SQL commands on the underlying database.
Mitigation:
Update to a version higher than 5.2.1. Ensure that magic_quotes are turned on.