← Back to CVE search

CVE-2016-20065

Product Catalog 8

Description

Product Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the selectedCategory parameter. Attackers can submit POST requests to the admin-ajax.php endpoint with the UpdateCategoryList action to extract sensitive database information from WordPress tables.

CVSS 8.2EPSS 0.27%Risk 0.84
View source
Published
2026-06-09 13:16:33
Affected versions
==1.2
Type
Installed app
Last modified
2026-07-21 07:10:00
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N