Add Edit Delete Listing Module [add-edit-delete-listing-for-member-module] <= 1.0 (closed)
unknown
[en] Vulnerability in wordpress plugin add-edit-delete-listing-for-member-module v1.0, The plugin author does not sanitize user supplied input via $act before passing it into an SQL statement.
- Affected:
- up to 1.0
- Fixed in:
- 1.0
- Disclosed:
- Sep 14, 2017
CVE-2017-1002025 on NVD →
Add Edit Delete Listing Module [add-edit-delete-listing-for-member-module] < 1.1 (closed)
unknown
Blind SQL Injection vulnerability found by Larry W. Cashdollar in WordPress Add Edit Delete Listing Module plugin 1.0 version. Passing unsanitized user supplied input via $act into an SQL statement. This vulnerability allows a user logged in as administrator to inject SQL statements into the query.
The plugin alread...
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Aug 17, 2017
Add Edit Delete Listing Module <= 1.0 - SQL Injection
high
Vulnerability in wordpress plugin add-edit-delete-listing-for-member-module v1.0, The plugin author does not sanitize user supplied input via $act before passing it into an SQL statement.
- CVSS:
- 7.2
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Jul 5, 2017
CVE-2017-1002025 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database