vendor:
WP Bannerize plugin
by:
Miroslav Stampar
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: WP Bannerize plugin
Affected Version From: <= 2.8.7
Affected Version To: 2.8.2007
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: WordPress
2011
WordPress WP Bannerize plugin <= 2.8.7 SQL Injection Vulnerability
The WordPress WP Bannerize plugin version 2.8.7 is vulnerable to SQL Injection. An attacker can exploit this vulnerability by sending malicious POST data to the ajax_sorter.php file, allowing them to execute arbitrary SQL queries.
Mitigation:
Update to the latest version of the plugin or remove it if not needed. Sanitize and validate user input before using it in SQL queries.