ZeroHour

CVE-2017-12947

CVSS 3.0
7.2 high
EPSS
1%p68
Published
()
Modified
Description

classes\controller\admin\modals.php in the Easy Modal plugin before 2.1.0 for WordPress has SQL injection in an untrash action with the id, ids, or modal parameter to wp-admin/admin.php, exploitable by administrators.

Vendors
easymodal project
Products
easy modal
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.