CVE-2014-2839

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
12/01/2015
Last modified:
12/04/2025

Description

SQL injection vulnerability in the GD Star Rating plugin 19.22 for WordPress allows remote administrators to execute arbitrary SQL commands via the s parameter in the gd-star-rating-stats page to wp-admin/admin.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dev4press:gd_star_rating:19.22:*:*:*:*:wordpress:*:*