CVE-2017-12650

CRITICAL

Loginizer < 1.3.5 - SQL Injection via X-Forwarded-For HTTP Header

Title source: llm
STIX 2.1

Description

SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_misc
https://wpvulndb.com/vulnerabilities/8883
Third Party Advisory x_refsource_confirm
https://sv.wordpress.org/plugins/loginizer/#developers

Scores

CVSS v3 9.8
EPSS 0.0184
EPSS Percentile 76.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
loginizer/loginizer < 1.3.5
Published Aug 07, 2017
Tracked Since Feb 18, 2026