CVE-2017-12947
—CVSS 3.0
7.2 high
EPSS
1%p68
Published
()
Modified
Description
classes\controller\admin\modals.php in the Easy Modal plugin before 2.1.0 for WordPress has SQL injection in an untrash action with the id, ids, or modal parameter to wp-admin/admin.php, exploitable by administrators.
- Vendors
- easymodal project
- Products
- easy modal
- Ecosystems
- WordPress
- Weakness
- CWE-89
- Vector
- CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.