CVE-2016-11000: SQL Injection
The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the exporttypename parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-11000?
The severity of CVE-2016-11000 is critical, with a CVSS score of 9.8.
How does CVE-2016-11000 affect WordPress?
CVE-2016-11000 affects WordPress through the wp-ultimate-exporter plugin version 1.1.
What is the vulnerability description for CVE-2016-11000?
CVE-2016-11000 is an SQL injection vulnerability in the wp-ultimate-exporter plugin version 1.1 for WordPress. It allows an attacker to inject SQL commands via the export_type_name parameter.
How can I fix CVE-2016-11000?
To fix CVE-2016-11000, update the wp-ultimate-exporter plugin to a version that is not vulnerable. It is recommended to upgrade to the latest version available.
Where can I find more information about CVE-2016-11000?
You can find more information about CVE-2016-11000 in the following references: [link1](https://seclists.org/bugtraq/2016/Feb/183) and [link2](https://wordpress.org/plugins/wp-ultimate-exporter/#developers).