WordPress security changelog
MEDIUM
CVE-2014-4944
Modified
Bsk Pdf Manager: SQL injection
Bsk Pdf Manager is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
CVE / CNA score
6.5
CVSS · cve@mitre.org
NVD score
6.5
CVSS 2.0 · nvd@nist.gov
- Component
- Bsk Pdf Manager
- Plugin slug
bsk-pdf-manager- Affected
- See vendor advisory
- Safe version
- See mitigation notes
- Published
- Jul 14, 2014
This CVE was published Jul 14, 2014 and is one of 7 known issues for this plugin.
What to do
Patch or disable the affected component.
Update Bsk Pdf Manager to a release outside the affected range, or disable and remove it until a fixed version is available.
Source record
Technical description
Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) categoryid or (2) pdfid parameter to wp-admin/admin.php.
NVD vector: AV:N/AC:L/Au:S/C:P/I:P/A:P
References