Multiple SQL injection vulnerabilities in the Huge-IT Slider (slider-image) plugin prior to 2.7.0 for WordPress allow remote administrators to execute arbitrary SQL commands via the removeslide parameter in a popup_posts or edit_cat action in the sliders_huge_it_slider page to wp-admin/admin.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
huge-it huge-it_slider |