First published: Fri Sep 20 2019(Updated: )
The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Smackcoders WP Ultimate Exporter | <=1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-11000 is critical, with a CVSS score of 9.8.
CVE-2016-11000 affects WordPress through the wp-ultimate-exporter plugin version 1.1.
CVE-2016-11000 is an SQL injection vulnerability in the wp-ultimate-exporter plugin version 1.1 for WordPress. It allows an attacker to inject SQL commands via the export_type_name parameter.
To fix CVE-2016-11000, update the wp-ultimate-exporter plugin to a version that is not vulnerable. It is recommended to upgrade to the latest version available.
You can find more information about CVE-2016-11000 in the following references: [link1](https://seclists.org/bugtraq/2016/Feb/183) and [link2](https://wordpress.org/plugins/wp-ultimate-exporter/#developers).