CVE-2020-24315

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
26/08/2020
Last modified:
14/02/2024

Description

Vinoj Cardoza WordPress Poll Plugin v36 and lower executes SQL statement passed in via the pollid POST parameter due to a lack of user input escaping. This allows users who craft specific SQL statements to dump the entire targets database.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wordpress_poll_project:wordpress_poll:*:*:*:*:*:wordpress:*:* 36.0 (including)