WP Rss Poster <= 1.0.0 - SQL Injection
criticalSQL injection vulnerability in the WP Rss Poster (wp-rss-poster) plugin 1.0.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in the wrp-add-new page to wp-admin/admin.php.
- CVSS:
- 9.8
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- May 28, 2014