vendor:
Helpful Plugin
by:
Numan Türle
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Helpful Plugin
Affected Version From: 2.4.11
Affected Version To: 2.4.11
Patch Exists: YES
Related CWE: N/A
CPE: 2.4.11
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2019
Helpful 2.4.11 Sql Injection – WordPress Plugin
The vulnerability exists due to insufficient sanitization of user-supplied input in the 'post_id' parameter of the 'helpful_ajax_pro' AJAX action of the 'helpful' plugin before using it in a SQL query. A remote attacker can send a specially crafted request to the vulnerable script and execute arbitrary SQL commands in the application's database, allowing to read, modify or delete data, compromise vulnerable system and potentially compromise other systems. The vulnerability is confirmed in version 2.4.11. Other versions may also be affected.
Mitigation:
Update to version 2.4.12 or later.