Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-113502. PoCs published by SEC Consult.
AI-analyzed exploit summary This advisory details multiple SQL injection vulnerabilities in WordPress versions 3.1.3 and 3.2-RC1, specifically in the `get_terms()` and `get_bookmarks()` functions. The vulnerabilities allow users with 'Editor' privileges to inject arbitrary SQL commands via the 'orderby' and 'order' parameters.
Description
WordPress Core 3.1.3 - SQL Injection
Exploits (1)
This advisory details multiple SQL injection vulnerabilities in WordPress versions 3.1.3 and 3.2-RC1, specifically in the `get_terms()` and `get_bookmarks()` functions. The vulnerabilities allow users with 'Editor' privileges to inject arbitrary SQL commands via the 'orderby' and 'order' parameters.