WordPress security changelog
HIGH
CVE-2014-3961
Modified
Participants Database: SQL injection
Participants Database is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
CVE / CNA score
7.5
CVSS · cve@mitre.org
NVD score
7.5
CVSS 2.0 · nvd@nist.gov
- Component
- Participants Database
- Plugin slug
participants-database- Affected
- See vendor advisory
- Safe version
- See mitigation notes
- Published
- Jun 04, 2014
This CVE was published Jun 04, 2014 and is one of 10 known issues for this plugin.
What to do
Patch or disable the affected component.
Update Participants Database to a release outside the affected range, or disable and remove it until a fixed version is available.
Source record
Technical description
SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the query parameter in an "output CSV" action to pdb-signup/.
NVD vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
References
Primary and upstream sources
- NVD record for CVE-2014-3961
- Upstream reference osvdb.org
- Upstream reference packetstormsecurity.com
- Upstream reference seclists.org
- Upstream reference exploit-db.com
- Upstream reference securityfocus.com
- WordPress.org plugin page wordpress.org
- Upstream reference yarubo.com
- Upstream reference osvdb.org
- Upstream reference packetstormsecurity.com
- Upstream reference seclists.org
- Upstream reference exploit-db.com
- Upstream reference securityfocus.com
- WordPress.org plugin page wordpress.org
- Upstream reference yarubo.com