WP-Download <= 1.2 - SQL Injection
criticalSQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the dl_id parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.2
- Fixed in:
- 1.2.1
- Disclosed:
- Mar 31, 2008