WordPress security changelog
HIGH CVE-2011-3130 Modified

WordPress component: SQL injection

WordPress component is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.

CVE / CNA score 7.5 CVSS · cve@mitre.org
NVD score 7.5 CVSS 2.0 · nvd@nist.gov
Component
WordPress component
Plugin slug
Core
Affected
See vendor advisory
Safe version
See mitigation notes
Published
Aug 10, 2011
Weakness
CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
NVD-CWE-noinfo

This CVE was published Aug 10, 2011 and is one of 45 known issues for WordPress core.

Patch or disable the affected component.

Update WordPress component to a release outside the affected range, or disable and remove it until a fixed version is available.

Technical description

wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardening," possibly involving SQL injection.

NVD vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Primary and upstream sources