Askeet <= 3.0 - Authenticated (Administrator+) SQL Injection via 'sql_query' Parameter
mediumThe Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (askeet_execute_sql_query, askeet_export_all_results) in all versions up to, and including, 3.0. This is due to the askeet_is_safe_query() filter being bypassable using MySQL conditional comments (e.g.,...
- CVSS:
- 4.9
- Affected:
- up to 3.0
- Fixed in:
- 3.1
- Disclosed:
- Aug 4, 2026