vendor:
FeedWordPress WordPress plugin
by:
Adrián M. F.
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: FeedWordPress WordPress plugin
Affected Version From: 2015.0426
Affected Version To: 2015.0514
Patch Exists: YES
Related CWE: CVE-2015-4018
CPE: a:feedwordpress_project:feedwordpress:2015.0426
Platforms Tested: WordPress
2015
SQLi in FeedWordPress WordPress plugin
Authenticated SQLi in the FeedWordPress WordPress plugin allows remote authenticated attackers to execute arbitrary SQL commands via the link_ids[] parameter in the feedwordpress/syndication.php page.
Mitigation:
Update to the fixed version (2015.0514) of the FeedWordPress WordPress plugin.