Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-5182

Multiple SQL injection vulnerabilities in the yawpp plugin 1.2 for WordPress allow remote authenticated users with Contributor privileges to execute arbitrary SQL commands via vectors related to (1) admin_functions.php or (2) admin_update.php, as demonstrated by the id parameter in the update action to wp-admin/admin.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.037
EPSS Ranking 87.5%
CVSS Severity
CVSS v2 Score 6.0
Products affected by CVE-2014-5182
  • Ostenta » Yawpp » Version: 1.2
    cpe:2.3:a:ostenta:yawpp:1.2


Contact Us

Shodan ® - All rights reserved