← Back

CVE-2014-5182

nvd nist
Published: Aug 6, 2014Modified: May 6, 2026

JSON object

Loading...
6.0
Vector
AV:N/AC:M/Au:S/C:P/I:P/A:P
Exploitability: 6.8 / Impact: 6.4
Source: NVD

Description

Multiple SQL injection vulnerabilities in the yawpp plugin 1.2 for WordPress allow remote authenticated users with Contributor privileges to execute arbitrary SQL commands via vectors related to (1) admin_functions.php or (2) admin_update.php, as demonstrated by the id parameter in the update action to wp-admin/admin.php.

Affected (1)

Products: Ostenta: Yawpp
1 product
Yawpp
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.2

Timeline

No history available yet.