Double Opt-In for Download <= 2.0.9 - SQL Injection
high
The Double Opt-In for Download Plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in versions up to, and including, 2.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated at...
- CVSS:
- 8.8
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.0
- Disclosed:
- Jun 6, 2016
Double Opt-In for Download <= 2.0.8 - SQL Injection
critical
Multiple SQL injection vulnerabilities in the Double Opt-In for Download plugin before 2.0.9 for WordPress allow remote attackers to execute arbitrary SQL commands via the ver parameter to (1) class-doifd-download.php or (2) class-doifd-landing-page.php in public/includes/.
- CVSS:
- 9.8
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.9
- Disclosed:
- Nov 24, 2015
CVE-2015-7517 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database