What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jewel Theme WP Adminify.This issue affects WP Adminify: from n/a through 3.1.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jewel Theme WP Adminify.This issue affects WP Adminify: from n/a through 3.1.6.
Explanation of Vulnerability in Simple Terms
WP Adminify versions up to 3.1.6 contain a SQL injection vulnerability in database queries. An attacker with high-level site privileges can craft malicious input to extract sensitive data from the database or disrupt site availability. The vulnerability requires administrative access to exploit.
What an attacker can do
Read sensitive data from the site database or cause temporary service disruption.
Potential impact on your site
If a rogue admin or compromised admin account exists, the site database can be queried or partially disabled.
Conditions required to exploit
Attacker must have high-level administrative privileges on the WordPress site.
Key dates
External resources
Related vulnerabilities