The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-05-05T14:17:40

Updated: 2024-08-04T11:48:58.138Z

Reserved: 2020-04-23T00:00:00

Link: CVE-2020-12104

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-05-05T15:15:12.420

Modified: 2020-05-07T20:16:35.347

Link: CVE-2020-12104

cve-icon Redhat

No data.