Description
An SQL Injection vulnerability exists in the league_id parameter of a function call made by the leaguemanager_export page.
Recommendation
To mitigate the risk, update the affected plugin to a secure version. If an update is not available or feasible, consider removing the plugin from your WordPress installation.
References
Related Issues
- WordPress Plugin Smart Google Code Inserter 3.5 SQLI - CVE-2018-3810
- WordPress Plugin Forum Server 1.7 SQLI - CVE-2012-6625
- WordPress Plugin AdRotate 3.6.5 SQLI - CVE-2011-4671
- WordPress Plugin AdRotate 3.6.6 SQLI - CVE-2011-4671
You might also like:
- Tags:
- Wordpress
- SQL Injection
Anything's wrong? Let us know Last updated on May 13, 2024


