First published: Mon Sep 30 2024(Updated: )
The Cost Calculator Builder WordPress plugin before 3.2.29 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
StylemixThemes Cost Calculator Builder | <3.2.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.