Description
Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to execute arbitrary SQL commands via the id parameter in a viewtopic (1) remove_post, (2) sticky, or (3) closed action or (4) thread parameter in a postreply action to index.php.
References (5)
Core 5
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/52167
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/90434
Vendor Advisory x_refsource_misc
http://secunia.com/secunia_research/2013-4
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/82188
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/58059
Scores
EPSS
0.0219
EPSS Percentile
80.6%
Details
CWE
CWE-89
Status
published
Products (44)
cartpauj/mingle-forum
1.0.00
cartpauj/mingle-forum
1.0.01
cartpauj/mingle-forum
1.0.02
cartpauj/mingle-forum
1.0.03
cartpauj/mingle-forum
1.0.04
cartpauj/mingle-forum
1.0.05
cartpauj/mingle-forum
1.0.06
cartpauj/mingle-forum
1.0.07
cartpauj/mingle-forum
1.0.08
cartpauj/mingle-forum
1.0.09
... and 34 more
Published
Apr 02, 2014
Tracked Since
Feb 18, 2026