CVE-2020-14092
WordPress PayPal Pro <1.1.65 - SQL Injection
Record summary
CVE-2020-14092 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALWordPress PayPal Pro <1.1.65 - SQL InjectionCVSS 9.8
WordPress PayPal Pro plugin before 1.1.65 is susceptible to SQL injection via the 'query' parameter which allows for any unauthenticated user to perform SQL queries with the results output to a web page in JSON format.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Update to the latest version of the WordPress PayPal Pro plugin (1.1.65 or higher) to mitigate the SQL Injection vulnerability.
Source: ProjectDiscovery