47475Third-party advisory
http://secunia.com/advisories/47475 CVE-2012-5350
WordPress Plugin Pay with Tweet 1.1 - Multiple Vulnerabilities
Record summary
CVE-2012-5350 has a selected CVSS score of 6.0; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the id parameter in a paywithtweet shortcode.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Pay with Tweet 1.1 - Multiple VulnerabilitiesExploitDB exploitby Gianluca BrindisiNot analyzed1 file
References
7wordpress.orgConfirmation
http://wordpress.org/extend/plugins/pay-with-tweet/changelog 18330exploit
http://www.exploit-db.com/exploits/18330 78204vdb entry
http://www.osvdb.org/78204 51308vdb entry
http://www.securityfocus.com/bid/51308 paywithtweet-postpage-sql-injection(72165)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/72165 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-5350