vendor:
Nexos Real Estate Agency Directory
by:
Vlad Vector
6.1
CVSS
MEDIUM
SQL Injection
79, 89
CWE
Product Name: Nexos Real Estate Agency Directory
Affected Version From: 1
Affected Version To: 1.7
Patch Exists: YES
Related CWE: CVE-2020-15363, CVE-2020-15364
CPE: a:sanljiljan:nexos_real_estate_agency_directory:1.7
Platforms Tested: Debian 10
2020
WordPress Theme NexosReal Estate 1.7 – ‘search_order’ SQL Injection
The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.
Mitigation:
Update the Nexos theme to the latest version.