Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-70738
HistorySep 08, 2021 - 12:00 a.m.

WordPress SQL Injection Vulnerability (CNVD-2021-70738)

2021-09-0800:00:00
China National Vulnerability Database
www.cnvd.org.cn
6

0.001 Low

EPSS

Percentile

45.2%

WordPress is a set of blogging platforms developed by the WordPress (Wordpress) Foundation using the PHP language. The platform supports setting up personal blog sites on servers with PHP and MySQL. WordPress plugin Embed Youtube Video 1.0 and earlier versions are vulnerable to SQL injection, which stems from the plugin’s editid GET parameter not being cleaned, escaped or validated before being inserted into SQL statements, leading to SQL injection. An attacker could use this vulnerability to obtain sensitive database information.

CPENameOperatorVersion
wordpress embed youtube videole1.0

0.001 Low

EPSS

Percentile

45.2%