stripShow Plugin <= 2.5.2 - SQL Injection
highSQL injection vulnerability in the stripshow-storylines page in the stripShow plugin 2.5.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the story parameter in an edit action to wp-admin/admin.php.
- CVSS:
- 7.2
- Affected:
- up to 2.5.2
- Fix:
- No patched version reported
- Disclosed:
- May 28, 2014