Description
|
|
Miroslav Stampar has discovered a vulnerability in the Mingle Forum plugin for WordPress, which can be exploited by malicious people to conduct SQL injection attacks.
Input passed to the "edit_post_id" parameter in wp-content/plugins/mingle-forum/wpf-insert.php is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
The vulnerability is confirmed in version 1.0.31. Other versions may also be affected.
|