CVE-2011-4669

WordPress Users < 1.3 - SQL Injection via uid Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in wp-users.php in WordPress Users plugin 1.3 and possibly earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the uid parameter to index.php.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/70683
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/50174
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46442

Scores

EPSS 0.0066
EPSS Percentile 71.4%

Details

CWE
CWE-89
Status published
Products (6)
wordpress/wordpress-users 0.2
wordpress/wordpress-users 0.9
wordpress/wordpress-users 1.0
wordpress/wordpress-users 1.1
wordpress/wordpress-users 1.2
wordpress/wordpress-users < 1.3
Published Dec 02, 2011
Tracked Since Feb 18, 2026