CVE-2013-1408
Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php.
Does this matter?
Lower severity and a low EPSS score (4.31%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 4.31% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- wysija newsletters project/wysija newsletters
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2013-02/0030.htmlExploit
- http://osvdb.org/89924
- http://packetstormsecurity.com/files/120089/WordPress-Wysija-Newsletters-2.2-SQL-Injection.htmlExploit
- http://www.securityfocus.com/bid/57775Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81932
- https://www.htbridge.com/advisory/HTB23140Exploit
- http://archives.neohapsis.com/archives/bugtraq/2013-02/0030.htmlExploit
- http://osvdb.org/89924
- http://packetstormsecurity.com/files/120089/WordPress-Wysija-Newsletters-2.2-SQL-Injection.htmlExploit
- http://www.securityfocus.com/bid/57775Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81932
- https://www.htbridge.com/advisory/HTB23140Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.