The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-05-05T14:17:40

Updated: 2020-05-05T14:17:40

Reserved: 2020-04-23T00:00:00


Link: CVE-2020-12104

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-05-05T15:15:12.420

Modified: 2020-05-07T20:16:35.347


Link: CVE-2020-12104

JSON object: View

cve-icon Redhat Information

No data.

CWE