cleantalk
Vulnerabilities and Security Researches

wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin, CVE-2014-9175

CVE, Research URL

CVE-2014-9175

Published on
Dec 02, 2014
Research Description
SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the table_id parameter in a get_wdtable action to wp-admin/admin-ajax.php.
Affected versions
Min -, max 1.5.4.
Status
vulnerable