Posted by Adrián M . F . on May 19
======================================================
SQLi in FeedWordPress WordPress plugin
======================================================
vendor: https://wordpress.org/plugins/feedwordpress/
active installs: 70,000+
vulnerable version: 2015.0426
fixed version: 2015.0514
CVE: CVE-2015-4018
Vulnerability
===============
(1) Authenticated SQLi [CWE-89]
——————————-
* CODE:
feedwordpresssyndicationpage.class.php:89…