Title Experiments Free < 9.0.1 - Unauthenticated SQLi
45Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actepss 10%
de la publicación al arma
Publicada en NVD28 mar
VulnCheck+609d
probabilidad de explotación
10%top 5% de las CVE
explotación observada
síVulnCheck
The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection
Productos afectados
Unknown · Title Experiments Free