CVE-2015-9448: SQL Injection
The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid parameter.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability CVE-2015-9448?
The vulnerability CVE-2015-9448 is a SQL Injection vulnerability in the sendpress plugin before version 1.2 for WordPress.
How does the vulnerability CVE-2015-9448 work?
The vulnerability CVE-2015-9448 works by allowing an attacker to execute malicious SQL queries through the sp-queue listid parameter in the wp-admin/admin.php?page=sp-queue page.
What is the severity rating of vulnerability CVE-2015-9448?
The severity rating of vulnerability CVE-2015-9448 is high with a severity value of 8.8.
How can I fix vulnerability CVE-2015-9448?
To fix vulnerability CVE-2015-9448, update the sendpress plugin to version 1.2 or newer.
Where can I find more information about vulnerability CVE-2015-9448?
You can find more information about vulnerability CVE-2015-9448 on the following references: http://cinu.pl/research/wp-plugins/mail_8a2f7613577ea8e613ec274aeec14527.html, https://wordpress.org/plugins/sendpress/#developers, https://wpvulndb.com/vulnerabilities/8324