Record summary

CVE-2020-14092 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress PayPal Pro <1.1.65 - SQL InjectionCVSS 9.8

WordPress PayPal Pro plugin before 1.1.65 is susceptible to SQL injection via the 'query' parameter which allows for any unauthenticated user to perform SQL queries with the results output to a web page in JSON format.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.

Remediation

Update to the latest version of the WordPress PayPal Pro plugin (1.1.65 or higher) to mitigate the SQL Injection vulnerability.

WeaknessesCWE-89
Authorsprincechaddha
Template tagscvecve2020wp-pluginsqlipaypalwpscanwordpressithemesvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:ithemes:paypal_pro:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

4