CVE-2017-16510: SQL Injection
Published Nov 1, 2017
·Updated
WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.
Affected Software
2 affected componentsFixes available
debian/wordpress
5.0.15+dfsg1-0+deb10u15.0.19+dfsg1-0+deb10u15.7.8+dfsg1-0+deb11u26.1.1+dfsg1-16.3.1+dfsg1-1
WordPress<=4.8.2
Remediation
Event History
Nov 1, 2017
Data Sourced
07:45 PM
SeverityAffected Software
Nov 2, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-16510?
CVE-2017-16510 has a high severity rating due to the potential for SQL injection attacks.
2
How do I fix CVE-2017-16510?
To fix CVE-2017-16510, upgrade WordPress to version 4.8.3 or later.
3
What versions of WordPress are affected by CVE-2017-16510?
WordPress versions prior to 4.8.3 are affected by CVE-2017-16510.
4
What kind of attack does CVE-2017-16510 enable?
CVE-2017-16510 enables potential SQL injection attacks through unsafe query preparations.
5
Is CVE-2017-16510 related to any other vulnerabilities?
CVE-2017-16510 is a different vulnerability than CVE-2017-14723, though both are related to SQL injection risks.