CVE-2014-7959

BulletProof Security < .51.1 - Authenticated SQL Injection via tableprefix Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tableprefix parameter.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70918
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/533904/100/0/threaded
Patch, Vendor Advisory x_refsource_confirm
https://wordpress.org/plugins/bulletproof-security/changelog/

Scores

EPSS 0.0210
EPSS Percentile 79.7%

Details

CWE
CWE-89
Status published
Products (50)
ait-pro/bulletproof_security .44
ait-pro/bulletproof_security .44.1
ait-pro/bulletproof_security .45
ait-pro/bulletproof_security .45.1
ait-pro/bulletproof_security .45.2
ait-pro/bulletproof_security .45.3
ait-pro/bulletproof_security .45.4
ait-pro/bulletproof_security .45.5
ait-pro/bulletproof_security .45.6
ait-pro/bulletproof_security .45.7
... and 40 more
Published Nov 06, 2014
Tracked Since Feb 18, 2026