Description
The StopBadBots WordPress plugin before 6.60 did not validate or escape the order and orderby GET parameter in some of its admin dashboard pages, leading to Authenticated SQL Injections
References
https://plugins.trac.wordpress.org/changeset/2576276/
https://wpscan.com/vulnerability/ffa1f718-f2c5-48ef-8eea-33a18a628a2c
https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=29174
https://plugins.trac.wordpress.org/changeset/2576276/
https://wpscan.com/vulnerability/ffa1f718-f2c5-48ef-8eea-33a18a628a2c
https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=29174
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.8 · High
Information
Source identifier
Vulnerability status
Modified
Published
2021-09-13T18:15:18.947Z
4 years agoLast modified
2026-01-16T19:23:16.610Z
2 months ago