CVE Database
/

CVE-2015-2199

Back to search

CVE-2015-2199

Published: Mar 3, 2015

Modified: Sep 16, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote authenticated users to execute arbitrary SQL commands via the item[id] parameter in a wonderplugin_audio_save_item action to wp-admin/admin-ajax.php or remote administrators to execute arbitrary SQL commands via the itemid parameter in the (2) wonderplugin_audio_show_item, (3) wonderplugin_audio_show_items, or (4) wonderplugin_audio_edit_item page to wp-admin/admin.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

118508
vdb-entry
x_refsource_OSVDB
36086
exploit
x_refsource_EXPLOIT-DB
118509
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now