CVE-2014-5184

stripshow 2.5.2 - Authenticated SQL Injection via Story Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the stripshow-storylines page in the stripShow plugin 2.5.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the story parameter in an edit action to wp-admin/admin.php.

References (1)

Core 1

Scores

EPSS 0.0158
EPSS Percentile 73.0%

Details

CWE
CWE-89
Status published
Products (1)
stripshow_plugin_project/stripshow 2.5.2
Published Aug 06, 2014
Tracked Since Feb 18, 2026