CVE-2015-3325

WP Symposium < 15.2 - SQL Injection via Forum Show Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-3325. PoCs published by Hannes Trunde.

AI-analyzed exploit summary The exploit details a blind SQL injection vulnerability in the WordPress WP Symposium Plugin version 15.1 and below. The vulnerability arises from insufficient input validation in the 'show' parameter, allowing attackers to inject malicious SQL queries.

Description

SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the show parameter in the QUERY_STRING to the default URI.

Exploits (1)

exploitdb WRITEUP
by Hannes Trunde · textwebappsphp
https://www.exploit-db.com/exploits/37080

The exploit details a blind SQL injection vulnerability in the WordPress WP Symposium Plugin version 15.1 and below. The vulnerability arises from insufficient input validation in the 'show' parameter, allowing attackers to inject malicious SQL queries.

Classification
Writeup 100%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: WordPress WP Symposium Plugin 15.1 (and below)
No auth needed
Prerequisites: Access to the vulnerable WordPress site with the WP Symposium Plugin installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/74237
Exploit exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/37080/

Scores

EPSS 0.0477
EPSS Percentile 90.8%

Details

CWE
CWE-89
Status published
Products (1)
wpsymposium/wp_symposium < 15.2
Published May 15, 2015
Tracked Since Feb 18, 2026