CVE-2014-5389

Content Audit < 1.6.1 - SQL Injection via Audited Content Types Option

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in content-audit-schedule.php in the Content Audit plugin before 1.6.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "Audited content types" option in the content-audit page to wp-admin/options-general.php.

Scores

EPSS 0.0233
EPSS Percentile 81.8%

Details

CWE
CWE-89
Status published
Products (2)
content_audit_project/content_audit 1.6
content_audit_project/content_audit 1.6.0
Published Oct 06, 2014
Tracked Since Feb 18, 2026