Vigil@nce - WordPress Query Interface: SQL injection

This bulletin was written by Vigil@nce : http://vigilance.fr/offer

SYNTHESIS OF THE VULNERABILITY

An attacker can use a SQL injection of WordPress Query Interface,
in order to read or alter data.

Impacted products: WordPress Plugins

Severity: 2/4

Creation date: 03/06/2014

DESCRIPTION OF THE VULNERABILITY

The WordPress Query Interface product uses a database.

However, user’s data are directly inserted in a SQL query.

An attacker can therefore use a SQL injection of WordPress Query
Interface, in order to read or alter data.

ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN

http://vigilance.fr/vulnerability/WordPress-Query-Interface-SQL-injection-14833

Articles similaires

Security Vulnerability

7 October 2026

Vigilance.fr - Adminer: multiple vulnerabilities dated 07/08/2026

An attacker can use several vulnerabilities of Adminer, dated 07/08/2026.

Security Vulnerability

7 October 2026

Vigilance.fr - Progress Telerik UI for AJAX: multiple vulnerabilities dated 07/08/2026

An attacker can use several vulnerabilities of Progress Telerik UI for AJAX, dated 07/08/2026.

Security Vulnerability

7 October 2026

Vigilance.fr - TeamPass: two vulnerabilities dated 07/08/2026

An attacker can use several vulnerabilities of TeamPass, dated 07/08/2026.