What the vulnerability does
01Description
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Explanation of Vulnerability in Simple Terms
The ACPT (Pro) Custom Post Types plugin for WordPress versions up to 2.0.63 contains a SQL injection vulnerability in a component requiring low-level authentication. An authenticated attacker can craft malicious input to execute arbitrary SQL queries, potentially reading sensitive database content or disrupting site availability. The vulnerability affects multiple users and components due to scope change.
What an attacker can do
Read sensitive database content or cause the site database to become unavailable.
Potential impact on your site
Attackers with basic WordPress accounts can steal data from your database or crash your site's database functionality.
Conditions required to exploit
Attacker must have a WordPress user account with low-level privileges (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities