Comment Highlighter <= 0.13 - Authenticated (Admin+) SQL Injection
highA c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
- CVSS:
- 7.2
- Affected:
- up to 0.13
- Fix:
- No patched version reported
- Disclosed:
- Jul 23, 2021