WatuPRO < 5.5.3.7 - SQL Injection
critical
SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the watupro_questions parameter in a watupro_submit action to wp-admin/admin-ajax.php.
- CVSS:
- 9.8
- Affected:
- up to 5.5.3.7
- Fixed in:
- 5.5.3.7
- Disclosed:
- Jul 3, 2017
CVE-2017-9834 on NVD →
WatuPRO < 4.9.0.8 - Cross-Site Request Forgery
medium
The Watu Pro plugin before 4.9.0.8 for WordPress has CSRF that allows an attacker to delete quizzes.
- CVSS:
- 4.3
- Affected:
- up to 4.9.0.8
- Fixed in:
- 4.9.0.8
- Disclosed:
- Sep 1, 2015
CVE-2015-9418 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database