Lead Octopus Power < 1.1.1 - SQL Injection
criticalSQL injection vulnerability in lib/optin/optin_page.php in the Lead Octopus plugin before 1.1.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.1
- Disclosed:
- Jul 28, 2014