What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedProd Pro allows SQL Injection.This issue affects SeedProd Pro: from n/a through 6.18.10.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedProd Pro allows SQL Injection.This issue affects SeedProd Pro: from n/a through 6.18.10.
Explanation of Vulnerability in Simple Terms
SeedProd Pro versions up to 6.18.10 contain a SQL injection vulnerability in a high-privilege function. An authenticated admin can craft malicious input to read or modify database contents. The vulnerability affects the site's database integrity and confidentiality. Update to a version newer than 6.18.10 to remediate.
What an attacker can do
Read or modify database records by injecting SQL commands through an admin function.
Potential impact on your site
An admin account compromise could expose or alter your site's database, including user data and settings.
Conditions required to exploit
Attacker must have admin-level access to the WordPress site.
Key dates
External resources
Related vulnerabilities