CVE-2015-9457: SQL Injection
Published Oct 10, 2019
·Updated
The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::listlinks SQL injection via the group parameter.
Affected Software
2 affected components
Caseproof Pretty Link<1.6.8
Caseproof Prettylinks<1.6.8
Event History
Oct 10, 2019
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2015-9457?
CVE-2015-9457 has a moderate severity rating due to its potential for SQL injection attacks.
2
How do I fix CVE-2015-9457?
To fix CVE-2015-9457, update the Pretty Links plugin to version 1.6.8 or higher.
3
What are the consequences of exploiting CVE-2015-9457?
Exploiting CVE-2015-9457 could allow an attacker to execute arbitrary SQL queries on the database.
4
Which versions of the Pretty Links plugin are affected by CVE-2015-9457?
CVE-2015-9457 affects versions of the Pretty Links plugin prior to 1.6.8.
5
Who is affected by CVE-2015-9457?
Users of the Pretty Links plugin for WordPress, specifically versions before 1.6.8, are affected by CVE-2015-9457.