10 High
AI Score
Confidence
High
0.002 Low
EPSS
Percentile
61.1%
The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED variable.
cinu.pl/research/wp-plugins/mail_576345187f5867ec8921b12de5884fb1.html
wordpress.org/plugins/wti-like-post/#developers
wpvulndb.com/vulnerabilities/8318