CVE-2020-12104: SQL Injection
Published May 5, 2020
·Updated
The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation.
Affected Software
2 affected components
Internet-formation Wp-advanced-search Wordpress<3.3.7
Wp-advanced-search Project Wp-advanced-search Wordpress<3.3.7
Event History
May 5, 2020
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the wp-advanced-search plugin?
The vulnerability ID for the wp-advanced-search plugin is CVE-2020-12104.
2
What is the severity level of CVE-2020-12104?
The severity level of CVE-2020-12104 is high (8.8).
3
How does the vulnerability in the wp-advanced-search plugin occur?
The vulnerability in the wp-advanced-search plugin occurs due to authenticated SQL injection via an uploaded .sql file.
4
What is the affected version of the wp-advanced-search plugin?
The affected version of the wp-advanced-search plugin is 3.3.6.
5
How can an attacker exploit CVE-2020-12104?
An attacker can exploit CVE-2020-12104 by executing SQL commands without any validation.