The Cookie Notification Plugin for WordPress plugin prior to 1.0.9 does not sanitise or escape the id GET parameter before using it in a SQL statement, when retrieving the setting to edit in the admin dashboard, leading to an authenticated SQL Injection
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
accesspressthemes wp cookie user info |