First published: Mon Dec 03 2018(Updated: )
There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable blind SQL injection vulnerability via the del_ids variable by POST request.
Credit: larry0@me.com
Affected Software | Affected Version | How to fix |
---|---|---|
Kibokolabs Arigato Autoresponder And Newsletter | =2.5.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1002000 is a blind SQL injection vulnerability in WordPress Arigato Autoresponder and Newsletter v2.5.1.8.
CVE-2018-1002000 has a severity rating of 7.2 (high).
The affected software version is Arigato Autoresponder and Newsletter v2.5.1.8 for WordPress.
CVE-2018-1002000 can be exploited by using the del_ids variable in a POST request.
To fix CVE-2018-1002000, update to a version of Arigato Autoresponder and Newsletter that does not have the vulnerability.