← Voltar à pesquisa de CVEs

CVE-2016-20073

Answer My Question

Descrição

Answer My Question 1.3 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the -id- POST parameter. Attackers can submit crafted SQL statements to the modal.php endpoint to extract sensitive database information including WordPress terms and configuration data.

CVSS 8.2EPSS 0.27%Risco 0.84
Ver fonte
Publicação
2026-06-15 14:16:30
Versões afetadas
==1.3
Tipo
Aplicação web
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N