CVE-2016-10950: SQL Injection
Published Sep 13, 2019
·Updated
The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter.
Affected Software
1 affected component
Sirv Sirv Wordpress<1.3.2
Event History
Sep 13, 2019
CVE Published
via MITRE·12:08 PM
Data Sourced
via MITRE·12:08 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10950?
CVE-2016-10950 is classified as a medium severity vulnerability due to the potential for SQL injection.
2
How do I fix CVE-2016-10950?
To fix CVE-2016-10950, update the Sirv plugin to version 1.3.2 or later.
3
What software is affected by CVE-2016-10950?
CVE-2016-10950 affects the Sirv plugin for WordPress, specifically versions prior to 1.3.2.
4
What is SQL injection in the context of CVE-2016-10950?
In the context of CVE-2016-10950, SQL injection occurs when an attacker exploits the id parameter to manipulate the database.
5
Can I use the Sirv plugin if it has CVE-2016-10950?
It is highly recommended to update the Sirv plugin to avoid security risks associated with CVE-2016-10950.