vendor:
Super CAPTCHA plugin
by:
Miroslav Stampar
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Super CAPTCHA plugin
Affected Version From: 2.2.2004
Affected Version To: 2.2.2004
Patch Exists: NO
Related CWE:
CPE: a:wordpress:super_captcha:2.2.4
Platforms Tested: WordPress
2011
WordPress Super CAPTCHA plugin <= 2.2.4 SQL Injection Vulnerability
The WordPress Super CAPTCHA plugin version 2.2.4 is vulnerable to SQL injection. An attacker can exploit this vulnerability by sending a specially crafted request to the 'markspam' parameter in the 'admin.php' page of the plugin. This allows the attacker to execute arbitrary SQL queries on the underlying database.
Mitigation:
Upgrade to a patched version of the plugin or remove it from the WordPress installation.