CVE-2018-10969

CRITICAL

Genetechsolutions Pie Register < 3.0.10 - SQL Injection

Title source: rule

Description

SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid.

Exploits (1)

exploitdb WORKING POC
by Manuel García Cárdenas · textwebappsphp
https://www.exploit-db.com/exploits/44867

Scores

CVSS v3 9.8
EPSS 0.1873
EPSS Percentile 95.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
genetechsolutions/pie_register < 3.0.10
Published Jun 17, 2018
Tracked Since Feb 18, 2026