7.5
CVSSv2

CVE-2015-3325

Published: 15/05/2015 Updated: 25/06/2015
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in forum.php in the WP Symposium plugin prior to 15.4 for WordPress allows remote malicious users to execute arbitrary SQL commands via the show parameter in the QUERY_STRING to the default URI.

Vulnerable Product Search on Vulmon Subscribe to Product

wpsymposium wp symposium

Exploits

======================================================================= title: SQL Injection product: WordPress WP Symposium Plugin vulnerable version: 151 (and probably below) fixed version: 154 CVE number: CVE-2015-3325 impact: CVSS Base Score 75 (AV:N/AC:L/Au:N/C:P/I:P/A:P) ho ...
WordPress WP Symposium plugin version 151 suffers from a remote SQL injection vulnerability ...