Lucene search

K
wpvulndbWpvulndbWPVDB-ID:24DC3B80-C930-4464-BFA2-E230D4D4AF53
HistoryNov 16, 2023 - 12:00 a.m.

GD Security Headers < 1.7.1 - Admin+ SQLi

2023-11-1600:00:00
wpscan.com
5
gd security headers
sql injection
admin privilege
sql sanitization

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.3%

Description The plugin does not properly sanitise and escape the filter-vd and filter-ed parameters before using them in SQL statements, leading to SQL injections exploitable by high privilege users such as admin

CPENameOperatorVersion
eq1.7.1

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.3%

Related for WPVDB-ID:24DC3B80-C930-4464-BFA2-E230D4D4AF53