SQL Injection Vulnerabilities in WP Forum wordpress plugin
Advisory ID: | HTB22859 |
Product: | WP Forum wordpress plugin |
Vendor: | Fredrik Fahlstad |
Vulnerable Versions: | 1.7.8 and probably prior |
Tested Version: | 1.7.8 |
Advisory Publication: | February 15, 2011 [without technical details] |
Vendor Notification: | February 15, 2011 |
Public Disclosure: | March 1, 2011 |
Vulnerability Type: | SQL Injection [CWE-89] |
Risk Level: | High |
CVSSv2 Base Score: | 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) |
Solution Status: | Fixed by Vendor |
Discovered and Provided: | High-Tech Bridge Security Research Lab |
Advisory Details: | |
High-Tech Bridge SA Security Research Lab has discovered multiple vulnerabilities in WP Forum wordpress plugin which could be exploited to perform SQL injection attacks. | |
Solution: | |
Upgrade to WP Forum version 2.4 More Information: http://fahlstad.se/wordpress/plugins/wp-forum/ | |
References: | |
[1] High-Tech Bridge Advisory HTB22859 - https://www.immuniweb.com/advisory/HTB22859 - SQL Injection Vulnerabilities in WP Forum wordpress plugin [2] WP Forum wordpress plugin - fahlstad.se - WP Forum is a WordPress plugin that enables you to have a forum directly attached to your WordPress installation [3] Common Weakness Enumeration (CWE) - http://cwe.mitre.org - targeted to developers and security practitioners, CWE is a formal list of software weakness types. | |
HTB22846: Multiple Vulnerabilities in IWantOneButton WordPress Plugin
Please feel free to send us any additional information related to this Advisory, such as vulnerable versions, additional exploitation details and conditions, patches and other relevant details.