WP-Cal <= 0.3 - SQL Injection
criticalSQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVSS:
- 9.8
- Affected:
- up to 0.3
- Fix:
- No patched version reported
- Disclosed:
- Jan 27, 2008