CVE-2013-6243
Landing Pages Plugin < 1.2.3 - SQL Injection via Post Parameter
Title source: llmDescription
SQL injection vulnerability in the Landing Pages plugin 1.2.3, before 20131009, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the "post" parameter to index.php.
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/87803
Exploit, Patch x_refsource_confirm
http://plugins.trac.wordpress.org/changeset?reponame=&old=785535%40landing-pages&new=785535%40landing-pages
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/98334
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/55192
Product x_refsource_confirm
http://wordpress.org/plugins/landing-pages/changelog
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/62942
Scores
EPSS
0.0249
EPSS Percentile
82.9%
Details
CWE
CWE-89
Status
published
Products (27)
landing_pages_project/landing_pages_plugin
1.0.3.7
landing_pages_project/landing_pages_plugin
1.0.3.8
landing_pages_project/landing_pages_plugin
1.0.3.9
landing_pages_project/landing_pages_plugin
1.0.4.1
landing_pages_project/landing_pages_plugin
1.0.4.2
landing_pages_project/landing_pages_plugin
1.0.4.4
landing_pages_project/landing_pages_plugin
1.0.5.1
landing_pages_project/landing_pages_plugin
1.0.5.3
landing_pages_project/landing_pages_plugin
1.0.5.6
landing_pages_project/landing_pages_plugin
1.0.7.1
... and 17 more
Published
Oct 23, 2013
Tracked Since
Feb 18, 2026