CVE-2017-5611: SQL Injection
SQL injection vulnerability in wp-includes/class-wp-query.php in WPQuery in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5611?
CVE-2017-5611 has been classified as high severity due to the potential for remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2017-5611?
To fix CVE-2017-5611, update WordPress to version 4.7.2 or later and ensure all plugins and themes are also updated.
Which versions of WordPress are affected by CVE-2017-5611?
WordPress versions prior to 4.7.2 are vulnerable to CVE-2017-5611.
Can CVE-2017-5611 be exploited through any plugin?
Yes, CVE-2017-5611 can be exploited if a plugin or theme mishandles a crafted post type name in WordPress.
Are any other applications affected by CVE-2017-5611?
CVE-2017-5611 primarily affects WordPress, but other applications such as specific versions of Oracle Data Integrator and Debian Linux may also be susceptible depending on their configurations.