WordPress security changelog
HIGH CVE-2014-3961 Modified

Participants Database: SQL injection

Participants Database is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.

CVE / CNA score 7.5 CVSS · cve@mitre.org
NVD score 7.5 CVSS 2.0 · nvd@nist.gov
Component
Participants Database
Plugin slug
participants-database
Affected
See vendor advisory
Safe version
See mitigation notes
Published
Jun 04, 2014
Weakness
CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

This CVE was published Jun 04, 2014 and is one of 10 known issues for this plugin.

Patch or disable the affected component.

Update Participants Database to a release outside the affected range, or disable and remove it until a fixed version is available.

Technical description

SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the query parameter in an "output CSV" action to pdb-signup/.

NVD vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Primary and upstream sources