The Testimonial WordPress Plugin WordPress plugin prior to 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
accesspressthemes ap custom testimonial |