CVE-2020-14092: SQL Injection
Published Jul 2, 2020
·Updated
The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.
Affected Software
1 affected component
iThemes Paypal Pro Wordpress<1.1.65
Event History
Jul 2, 2020
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2020-14092.
2
What is the severity of CVE-2020-14092?
The severity of CVE-2020-14092 is critical with a CVSS score of 9.8.
3
What is the affected software of CVE-2020-14092?
The affected software of CVE-2020-14092 is the CodePeople Payment Form for PayPal Pro plugin before version 1.1.65 for WordPress.
4
How can the SQL Injection vulnerability in CVE-2020-14092 be exploited?
The SQL Injection vulnerability in CVE-2020-14092 can be exploited by an attacker injecting malicious SQL queries into user input fields.
5
How can I fix the SQL Injection vulnerability in CVE-2020-14092?
To fix the SQL Injection vulnerability in CVE-2020-14092, update the CodePeople Payment Form for PayPal Pro plugin to version 1.1.65 or higher.