First published: Fri Jun 08 2007(Updated: )
SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value in an XML RPC wp.suggestCategories methodCall, a different vector than CVE-2007-1897.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3140 is classified as a high severity vulnerability due to the potential for remote authenticated users to execute arbitrary SQL commands.
To fix CVE-2007-3140, you should upgrade your WordPress installation to a version higher than 2.2, as this vulnerability has been resolved in later releases.
CVE-2007-3140 affects WordPress version 2.2, specifically when accessed by remote authenticated users.
CVE-2007-3140 is classified as an SQL injection vulnerability, allowing execution of arbitrary SQL commands.
Exploitation of CVE-2007-3140 can lead to unauthorized access to the database, allowing attackers to manipulate data or execute administrative operations.