Gary Pendergast

1 exploit Active since Nov 2017
CVE-2017-16510 WRITEUP CRITICAL WRITEUP
WordPress < 4.8.3 - SQL Injection via Double Prepare Approach
WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.
CVSS 9.8