CVE-2015-2196
WordPress Plugin Webdorado Spider Event Calendar 1.4.9 - SQL Injection
Record summary
CVE-2015-2196 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Webdorado Spider Event Calendar 1.4.9 - SQL InjectionExploitDB exploitby Mateusz LachNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHWordPress Spider Calendar <=1.4.9 - SQL InjectionCVSS 7.5
WordPress Spider Calendar plugin through 1.4.9 is susceptible to SQL injection. An attacker can execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php, thus making it possible to obtain sensitive information, modify data, and/or execute unauthorized administrative operations.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or complete compromise of the WordPress site.
Remediation
Fixed in version 1.4.14.
Source: ProjectDiscovery