CVE-2012-5350: SQL Injection
Published Oct 9, 2012
·Updated
SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the id parameter in a paywithtweet shortcode.
Affected Software
2 affected components
WordPress Pay-with-tweet<=1.1
WordPress WordPress
Event History
Oct 9, 2012
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-5350?
CVE-2012-5350 is considered a medium severity vulnerability due to the potential for SQL injection by authenticated users.
2
How do I fix CVE-2012-5350?
To fix CVE-2012-5350, update the Pay With Tweet plugin to version 1.2 or later.
3
Who is affected by CVE-2012-5350?
CVE-2012-5350 affects users of the Pay With Tweet plugin for WordPress versions prior to 1.2.
4
What type of vulnerability is CVE-2012-5350?
CVE-2012-5350 is an SQL injection vulnerability that can allow arbitrary SQL commands to be executed.
5
Can CVE-2012-5350 be exploited remotely?
Yes, CVE-2012-5350 can be exploited remotely by authenticated users with specific permissions.