CVE-2014-5389
Content Audit < 1.6.1 - SQL Injection via Audited Content Types Option
Title source: llmDescription
SQL injection vulnerability in content-audit-schedule.php in the Content Audit plugin before 1.6.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "Audited content types" option in the content-audit page to wp-admin/options-general.php.
References (5)
Core 5
Core References
Exploit x_refsource_misc
http://packetstormsecurity.com/files/128525/WordPress-Content-Audit-1.6-Blind-SQL-Injection.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/70214
Exploit x_refsource_misc
https://security.dxw.com/advisories/blind-sqli-vulnerability-in-content-audit-could-allow-a-privileged-attacker-to-exfiltrate-password-hashes/
Exploit mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Oct/8
Product x_refsource_confirm
https://wordpress.org/plugins/content-audit/changelog
Scores
EPSS
0.0233
EPSS Percentile
81.8%
Details
CWE
CWE-89
Status
published
Products (2)
content_audit_project/content_audit
1.6
content_audit_project/content_audit
1.6.0
Published
Oct 06, 2014
Tracked Since
Feb 18, 2026