PT-2019-7425 · WordPress · Wti Like Post

Marcin Probola

·

Published

2019-10-10

·

Updated

2019-10-17

·

CVE-2015-9466

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions wti-like-post plugin versions prior to 1.4.3
Description The issue concerns SQL injection via the HTTP CLIENT IP, HTTP X FORWARDED FOR, HTTP X FORWARDED, HTTP FORWARDED FOR, or HTTP FORWARDED variable in the WtiLikePostProcessVote function.
Recommendations For versions prior to 1.4.3, update to version 1.4.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the WtiLikePostProcessVote function until a patch is available. Avoid using the variables HTTP CLIENT IP, HTTP X FORWARDED FOR, HTTP X FORWARDED, HTTP FORWARDED FOR, or HTTP FORWARDED in the affected function until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-9466

Affected Products

Wti Like Post