CVE-2018-11515: SQL Injection
Published May 28, 2018
·Updated
The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.
Affected Software
1 affected component
gVectors Wpforo Wordpress<1.4.5
Event History
May 28, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-11515?
CVE-2018-11515 is a SQL Injection vulnerability in the wpForo plugin for WordPress.
2
How severe is CVE-2018-11515?
CVE-2018-11515 has a severity rating of 9.8 (Critical).
3
How does CVE-2018-11515 affect software?
CVE-2018-11515 affects the wpForo plugin for WordPress version 1.4.5 and earlier.
4
How can I fix CVE-2018-11515?
To fix CVE-2018-11515, update the wpForo plugin to a version later than 1.4.5.
5
Where can I find more information about CVE-2018-11515?
More information about CVE-2018-11515 can be found in the references section.