vendor:
Simple:Press Wordpress Plugin
by:
ADEO Security
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Simple:Press Wordpress Plugin
Affected Version From: v4.3.0
Affected Version To: Possible all versions
Patch Exists: YES
Related CWE: N/A
CPE: a:simple-press:simple:press
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Simple:Press WordPress Plugin SQL Injection Vulnerability
In the search field, search values not filtered and inserted into sql queries without using any quotes/single quotes and Simple:Press execute this sql queries. Exploit code: http://[target]/wp-content/plugins/simple-press/sf-header-forum.php?search=1&value=[SQL]
Mitigation:
Update to the latest version of Simple:Press.