SQL Shortcode <= 1.1 - SQL Execution
highThe SQL Shortcode plugin for WordPress is vulnerable to SQL Execution in versions up to, and including, 1.1. This is due to the user inputted information being directly submitted to an SQL query. This makes it possible for authenticated attackers to execute arbitrary SQL code.
- CVSS:
- 8.8
- Affected:
- up to 1.1
- Fix:
- No patched version reported
- Disclosed:
- Sep 2, 2017