SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the link_ids[] parameter in an Update action in the syndication.php page to wp-admin/admin.php.
                
            References
                    | Link | Resource | 
|---|---|
| http://seclists.org/fulldisclosure/2015/May/75 | Exploit | 
| https://wordpress.org/plugins/feedwordpress/changelog/ | Patch Vendor Advisory | 
| http://packetstormsecurity.com/files/131974/WordPress-FeedWordPress-2015.0426-SQL-Injection.html | Exploit | 
| https://www.exploit-db.com/exploits/37067/ | Exploit | 
Configurations
                    Information
                Published : 2015-05-21 13:59
Updated : 2015-06-25 09:22
NVD link : CVE-2015-4018
Mitre link : CVE-2015-4018
JSON object : View
CWE
                
                    
                        
                        CWE-89
                        
            Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
                feedwordpress_project
- feedwordpress
 


