What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Trustindex.Io WP Testimonials.This issue affects WP Testimonials: from n/a through 1.4.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Trustindex.Io WP Testimonials.This issue affects WP Testimonials: from n/a through 1.4.3.
Explanation of Vulnerability in Simple Terms
WP Testimonials versions up to 1.4.3 contain a SQL injection vulnerability in a database query that requires administrator privileges to exploit. An attacker with admin access can craft malicious input to read sensitive data from the database or degrade site performance. The vulnerability affects the scope beyond the vulnerable component itself.
What an attacker can do
Read sensitive data from the site's database or cause performance degradation.
Potential impact on your site
If a compromised admin account exists, attackers can extract database contents or disrupt site availability.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site.
Key dates
External resources
Related vulnerabilities