Bestbooks <= 2.6.3 - Unauthenticated SQLi
40Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 9.2%
from disclosure to weapon
Published on NVDJun 13
VulnCheck+535d
exploitation probability
9.2%top 5% of all CVEs
observed exploitation
yesVulnCheck
The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users
Affected products
Unknown · Bestbooks