First published: Tue Jan 13 2015(Updated: )
SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Strategy11 Awp Classifieds Wordpress | =3.3.1 | |
Another Wordpress Classifieds Plugin | =3.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-10013 has a high severity rating due to its potential for remote SQL injection attacks.
To fix CVE-2014-10013, you should update the Another WordPress Classifieds Plugin to a patched version.
Users of Another WordPress Classifieds Plugin and Awp Classifieds version 3.3.1 are vulnerable to CVE-2014-10013.
SQL injection in CVE-2014-10013 allows attackers to execute arbitrary SQL commands via a vulnerable parameter in the plugin.
Yes, CVE-2014-10013 can potentially facilitate data breaches by allowing unauthorized access to sensitive information in the database.