Chop Slider 3 <= 3.4 - Unauthenticated SQL Injection
criticalA blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter supplied to get_script/index.php, and allows an attacker to execute arbitrary SQL queries in the context of the WP database user.
- CVSS:
- 9.8
- Affected:
- up to 3.4
- Fix:
- No patched version reported
- Disclosed:
- May 9, 2020