CVE-2013-3530

Fabricio Zuardi Xspf Player Plugin - SQL Injection

Title source: rule
STIX 2.1

Description

SQL injection vulnerability in playlist.php in the Spiffy XSPF Player plugin 0.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the playlist_id parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Ashiyane Digital Security Team · textwebappsphp
https://www.exploit-db.com/exploits/38441

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/83345
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/92258
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/58976

Scores

EPSS 0.0091
EPSS Percentile 75.8%

Details

CWE
CWE-89
Status published
Products (1)
fabricio_zuardi/xspf_player_plugin 0.1
Published May 10, 2013
Tracked Since Feb 18, 2026