CVE-2016-10949: SQL Injection
Published Sep 13, 2019
·Updated
The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization.
Affected Software
1 affected component
Relevanssi Relevanssi WordPress<1.14.6.1
Event History
Sep 13, 2019
CVE Published
via MITRE·12:06 PM
Data Sourced
via MITRE·12:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10949?
CVE-2016-10949 has a high severity rating due to its potential for SQL injection and unsafe unserialization.
2
How do I fix CVE-2016-10949?
To fix CVE-2016-10949, update the Relevanssi Premium plugin to version 1.14.6.1 or later.
3
What causes the vulnerability in CVE-2016-10949?
CVE-2016-10949 is caused by improper handling of database queries which allows SQL injection followed by unsafe unserialization.
4
Can CVE-2016-10949 be exploited by non-privileged users?
CVE-2016-10949 can potentially be exploited by non-privileged users if they can gain access to the vulnerable plugin's functionalities.
5
What are the potential impacts of CVE-2016-10949?
The impacts of CVE-2016-10949 could include unauthorized access to sensitive data and the execution of arbitrary code.