404like Plugin 404Like.php checkPage sql injection
Published Mar 20, 2023
9.8
CRITICALCVSS 3.1
EPSS 0.89%
Description
A vulnerability was found in 404like Plugin up to 1.0.2 on WordPress. It has been classified as critical. Affected is the function checkPage of the file 404Like.php. The manipulation of the argument searchWord leads to sql injection. It is possible to launch the attack remotely. Upgrading to version 1.0.2 is able to address this issue. The name of the patch is 2c4b589d27554910ab1fd104ddbec9331b540f7f. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-223404.
Affected products
- Vendor n/a Product 404like Plugin Defaultn/a
- Version 1.0.0StatusaffectedConstraints-
- Version 1.0.1StatusaffectedConstraints-
- Version 1.0.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | 404like Plugin | n/a |
|
- < 1.0.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2012-1031 Advisory
- https://github.com/wp-plugins/404like/commit/2c4b589d27554910ab1fd104ddbec9331b540f7f patch
- https://github.com/wp-plugins/404like/releases/tag/1.0.2 patchRelease Notes
- https://vuldb.com/?ctiid.223404 signaturepermissions-requiredPermissions RequiredThird Party Advisory
- https://vuldb.com/?id.223404 vdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2012-1031 | Advisory | |
| https://github.com/wp-plugins/404like/commit/2c4b589d27554910ab1fd104ddbec9331b540f7f | patch | |
| https://github.com/wp-plugins/404like/releases/tag/1.0.2 | patchRelease Notes | |
| https://vuldb.com/?ctiid.223404 | signaturepermissions-requiredPermissions RequiredThird Party Advisory | |
| https://vuldb.com/?id.223404 | vdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.