Envato Sales By Item <= 1.1 - Unauthenticated SQL Injection via AJAX call
mediumThe Envato Sales By Item plugin for WordPress fails to sanitize user input that is subsequently used in an SQL. It also lacks capability checks. An unauthenticated attacker could exploit this in versions up to 1.1.
- CVSS:
- 6.5
- Affected:
- up to 1.1
- Fix:
- No patched version reported
- Disclosed:
- May 26, 2022