6.5
CVSSv2

CVE-2014-6242

Published: 02/10/2014 Updated: 09/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin prior to 3.8.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby or (2) order parameter in the aiowpsec page to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote malicious users to execute arbitrary SQL commands.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tips and tricks hq all in one wordpress security and firewall

Exploits

Advisory ID: HTB23231 Product: All In One WP Security WordPress plugin Vendor: Tips and Tricks HQ, Peter, Ruhul, Ivy Vulnerable Version(s): 382 and probably prior Tested Version: 382 Advisory Publication: September 3, 2014 [without technical details] Vendor Notification: September 3, 2014 Vendor Patch: September 12, 2014 Public Disclosure: ...
WordPress All In One WP Security plugin version 382 suffers from multiple remote SQL injection vulnerabilities ...