Yes/No Chart < 1.0.12 - Authenticated SQL Injection
mediumThe Yes/No Chart WordPress plugin before 1.0.12 did not sanitise its sid shortcode parameter before using it in a SQL statement, allowing medium privilege users (contributor+) to perform Blind SQL Injection attacks.
- CVSS:
- 6.5
- Affected:
- up to 1.0.12
- Fixed in:
- 1.0.12
- Disclosed:
- May 31, 2021