vendor:
Mingle Forum plugin
by:
Miroslav Stampar
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Mingle Forum plugin
Affected Version From: 1.0.0
Affected Version To: 1.0.31
Patch Exists: NO
Related CWE:
CPE: a:wordpress:mingle_forum:1.0.31
Platforms Tested: WordPress
2011
WordPress Mingle Forum plugin <= 1.0.31 SQL Injection Vulnerability
This vulnerability allows an attacker to inject SQL queries into the WordPress Mingle Forum plugin version 1.0.31. By manipulating the POST data, an attacker can execute arbitrary SQL queries, potentially leading to unauthorized access or data leakage.
Mitigation:
Upgrade to a newer version of the Mingle Forum plugin that has fixed the SQL injection vulnerability.