CVE-2014-7959
BulletProof Security < .51.1 - Authenticated SQL Injection via tableprefix Parameter
Title source: llmDescription
SQL injection vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tableprefix parameter.
References (4)
Core 4
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/128977/WordPress-Bulletproof-Security-.51-XSS-SQL-Injection-SSRF.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/70918
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/533904/100/0/threaded
Patch, Vendor Advisory x_refsource_confirm
https://wordpress.org/plugins/bulletproof-security/changelog/
Scores
EPSS
0.0210
EPSS Percentile
79.7%
Details
CWE
CWE-89
Status
published
Products (50)
ait-pro/bulletproof_security
.44
ait-pro/bulletproof_security
.44.1
ait-pro/bulletproof_security
.45
ait-pro/bulletproof_security
.45.1
ait-pro/bulletproof_security
.45.2
ait-pro/bulletproof_security
.45.3
ait-pro/bulletproof_security
.45.4
ait-pro/bulletproof_security
.45.5
ait-pro/bulletproof_security
.45.6
ait-pro/bulletproof_security
.45.7
... and 40 more
Published
Nov 06, 2014
Tracked Since
Feb 18, 2026