Lucene search

K
wpexploitWpvulndbWPEX-ID:694B6DFD-2424-41B4-8595-B6C305C390DB
HistoryJul 18, 2022 - 12:00 a.m.

WPDating <= 7.1.9 - Multiple SQL Injection Issues

2022-07-1800:00:00
wpvulndb
75

0.002 Low

EPSS

Percentile

57.5%

The plugin does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities.

http://vulnerable-site.tld/wp-content/plugins/dsp_dating/m1/post_one.php?sender_id=(sender_id*sleep(10))&receiver_id=(sender_id*sleep(10))

0.002 Low

EPSS

Percentile

57.5%

Related for WPEX-ID:694B6DFD-2424-41B4-8595-B6C305C390DB