Description
|
|
Miroslav Stampar has discovered a vulnerability in the WP Forum Server plugin for WordPress, which can be exploited my malicious people to conduct SQL injection attacks.
Input passed to the "edit_post_id" POST parameter in wp-content/plugins/forum-server/wpf-insert.php (when "edit_post_submit" and "thread_id" are set) is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
The vulnerability is confirmed in version 1.7. Prior versions may also be affected.
|