cleantalk
Vulnerabilities and Security Researches

WordPress WP-Advanced-Search, CVE-2020-12104

CVE, Research URL

CVE-2020-12104

Published on
May 05, 2020
Research Description
The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation.
Affected versions
max 3.3.7.
Status
vulnerable