HomeDefault status
affected
Any version
affected
Description
The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated users, such as subscriber to perform SQLI attacks
Problem types
Product status
Any version
Credits
Yousof Nahya
WPScan
References
wpscan.com/...rability/aec53f87-6500-4c8a-925a-146be61bbabf/