CVE-2013-1408 EXPLOIT
6.5
MEDIUM · CVSS 2.0 · EPSS 4.3% (pctl 91)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.
Scoring
| CVSS | 6.5 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
| EPSS | 4.31% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-03-24 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| wysija newsletters project | wysija newsletters |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WordPress Plugin Wysija Newsletters - Multiple SQL Injections | 2013-02-06 |
References
- http://archives.neohapsis.com/archives/bugtraq/2013-02/0030.html
- http://osvdb.org/89924
- http://packetstormsecurity.com/files/120089/WordPress-Wysija-Newsletters-2.2-SQL-Injection.html
- http://www.securityfocus.com/bid/57775
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81932
- https://www.htbridge.com/advisory/HTB23140
- http://archives.neohapsis.com/archives/bugtraq/2013-02/0030.html
- http://osvdb.org/89924
- http://packetstormsecurity.com/files/120089/WordPress-Wysija-Newsletters-2.2-SQL-Injection.html
- http://www.securityfocus.com/bid/57775
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81932
- https://www.htbridge.com/advisory/HTB23140
→ the Explorer · watch your stack · NVD