CVE-2012-5350 EXPLOIT
6.0
MEDIUM · CVSS 2.0 · EPSS 2.4% (pctl 83)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the id parameter in a paywithtweet shortcode.
Scoring
| CVSS | 6.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:S/C:P/I:P/A:P |
| EPSS | 2.37% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-10-09 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| wordpress | pay-with-tweet |
| wordpress | wordpress |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WordPress Plugin Pay with Tweet 1.1 - Multiple Vulnerabilities | 2012-01-06 |
References
- http://secunia.com/advisories/47475
- http://wordpress.org/extend/plugins/pay-with-tweet/changelog/
- http://www.exploit-db.com/exploits/18330
- http://www.osvdb.org/78204
- http://www.securityfocus.com/bid/51308
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72165
- http://secunia.com/advisories/47475
- http://wordpress.org/extend/plugins/pay-with-tweet/changelog/
- http://www.exploit-db.com/exploits/18330
- http://www.osvdb.org/78204
- http://www.securityfocus.com/bid/51308
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72165
→ the Explorer · watch your stack · NVD