CVE-2018-16159: SQL Injection
Published Aug 30, 2018
·Updated
The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the templateid parameter in a wp-admin/admin-ajax.php wpgvdoajaxfronttemplate request.
Affected Software
1 affected component
Codemenschen Gift Vouchers Wordpress<=2.0.1
Event History
Aug 30, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16159?
CVE-2018-16159 has a medium severity rating due to its potential for unauthorized SQL injection attacks.
2
How do I fix CVE-2018-16159?
To fix CVE-2018-16159, update the Gift Vouchers plugin to version 2.0.2 or later.
3
What type of vulnerability is CVE-2018-16159?
CVE-2018-16159 is an SQL Injection vulnerability affecting the Gift Vouchers plugin for WordPress.
4
What software is affected by CVE-2018-16159?
The vulnerable software is the Gift Vouchers plugin for WordPress versions up to and including 2.0.1.
5
What is the impact of CVE-2018-16159?
The impact of CVE-2018-16159 includes the possibility of an attacker executing arbitrary SQL queries on the affected database.