CVE-2017-9834
07.09.2017, 14:29
SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the watupro_questions parameter in a watupro_submit action to wp-admin/admin-ajax.php.
Vendor | Product | Version |
---|---|---|
calendarscripts | watupro | 𝑥 ≤ 5.5.1 |
𝑥
= Vulnerable software versions