CVE-2011-5308
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
01/01/2015
Last modified:
12/04/2025
Description
Multiple SQL injection vulnerabilities in cdnvote-post.php in the cdnvote plugin before 0.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) cdnvote_post_id or (2) cdnvote_point parameter.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cdnvote_project:cdnvote:*:*:*:*:*:wordpress:*:* | 0.4.1 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://wpsecure.net/2011/02/cdnvote-plugin/
- https://plugins.trac.wordpress.org/changeset/350873/cdnvote/trunk/cdnvote-post.php
- https://www.htbridge.com/advisory/HTB22845
- http://wpsecure.net/2011/02/cdnvote-plugin/
- https://plugins.trac.wordpress.org/changeset/350873/cdnvote/trunk/cdnvote-post.php
- https://www.htbridge.com/advisory/HTB22845



