CRITICAL
The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED variable
Published Oct 10, 2019
9.8
CRITICALCVSS 3.1
EPSS 2.39%
Description
Affected products
Remediation
References (3)
Change history (0)
No recorded changes yet.