The Yes/No Chart WordPress plugin before 1.0.12 did not...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Jun 14, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 29, 2023
The Yes/No Chart WordPress plugin before 1.0.12 did not sanitise its sid shortcode parameter before using it in a SQL statement, allowing medium privilege users (contributor+) to perform Blind SQL Injection attacks
References