cleantalk
Vulnerabilities and Security Researches

Testimonial, CVE-2013-5673

CVE, Research URL

CVE-2013-5673

Application

Testimonial

Published on
Sep 11, 2013
Research Description
SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the custom_query parameter in a testimonial_add action to wp-admin/admin-ajax.php.
Affected versions
Min -, max 2.3.
Status
vulnerable