peter bassill · operator
$ cve CVE-2008-0520 JSON

CVE-2008-0520 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.9% (pctl 86)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) from_date or (2) to_date parameter to spy.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.85% — more likely to be exploited than 86% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2008-01-31
Last modified2026-06-16

Affected (1)

VendorProduct
wordpresswassup plugin

Public exploits

SourceTitleDate
exploit-dbWordPress Plugin WassUp 1.4.3 - 'to_date' SQL Injection2008-01-30

References

→ the Explorer  ·  watch your stack  ·  NVD