6.5
CVSSv2

CVE-2015-2199

Published: 03/03/2015 Updated: 04/03/2015
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin prior to 2.1 for WordPress allow (1) remote authenticated users to execute arbitrary SQL commands via the item[id] parameter in a wonderplugin_audio_save_item action to wp-admin/admin-ajax.php or remote administrators to execute arbitrary SQL commands via the itemid parameter in the (2) wonderplugin_audio_show_item, (3) wonderplugin_audio_show_items, or (4) wonderplugin_audio_edit_item page to wp-admin/admin.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wonderplugin audio player

Exploits

# Exploit Title: WonderPlugin Audio Player 20 Blind SQL Injection and XSS # Date: 20-01-2015 # Software Link: wwwwonderplugincom/wordpress-audio-player/ # Exploit Author: Kacper Szurek # Contact: twittercom/KacperSzurek # Website: securityszurekpl/ # Category: webapps 1 Description wp_ajax_save_item() is accessible f ...