Product Catalog 8 <= 1.2.0 - SQL Injection
criticalThe Product Catalog 8 plugin for WordPress is vulnerable to SQL Injection via the ‘selectedCategory’ parameter in versions up to, and including, 1.2.0 due to insufficient escaping on a user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append ad...
- CVSS:
- 9.8
- Affected:
- up to 1.2.0
- Fix:
- No patched version reported
- Disclosed:
- Nov 28, 2016