CVE-2015-9458
HIGHsearchterms-tagging-2 < 1.535 - SQL Injection via Popular Terms Count Parameter
Title source: llmDescription
The searchterms-tagging-2 plugin through 1.535 for WordPress has SQL injection via the pk_stt2_db_get_popular_terms count parameter exploitable via CSRF.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://wordpress.org/plugins/searchterms-tagging-2/#developers
Exploit, Third Party Advisory x_refsource_misc
http://cinu.pl/research/wp-plugins/mail_d14e213879cd60e80e538bde21c0359b.html
Scores
CVSS v3
7.2
EPSS
0.0176
EPSS Percentile
75.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
seo_searchterms_tagging_2_project/seo_searchterms_tagging_2
< 1.535
Published
Oct 10, 2019
Tracked Since
Feb 18, 2026