CVE-2012-5327

medium
Published 2012-10-08 · Modified 2026-04-29
CVSS v3
CVSS v2
6.5
VIR risk
6.5

Description

Multiple SQL injection vulnerabilities in fs-admin/fs-admin.php in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) delete_usrgrp[] parameter in a delete_usergroups action, (2) usergroup parameter in an add_user_togroup action, or (3) add_forum_group_id parameter in an add_forum_submit action.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
cartpaujmingle-forum{"endIncluding":"1.0.32.1"}
cartpaujmingle-forum1.0.00
cartpaujmingle-forum1.0.01
cartpaujmingle-forum1.0.02
cartpaujmingle-forum1.0.03
cartpaujmingle-forum1.0.04
cartpaujmingle-forum1.0.05
cartpaujmingle-forum1.0.06
cartpaujmingle-forum1.0.07
cartpaujmingle-forum1.0.08
cartpaujmingle-forum1.0.09
cartpaujmingle-forum1.0.10
cartpaujmingle-forum1.0.11
cartpaujmingle-forum1.0.12
cartpaujmingle-forum1.0.13
cartpaujmingle-forum1.0.14
cartpaujmingle-forum1.0.15
cartpaujmingle-forum1.0.16
cartpaujmingle-forum1.0.17
cartpaujmingle-forum1.0.18
cartpaujmingle-forum1.0.19
cartpaujmingle-forum1.0.20
cartpaujmingle-forum1.0.21
cartpaujmingle-forum1.0.21.1
cartpaujmingle-forum1.0.22
cartpaujmingle-forum1.0.23
cartpaujmingle-forum1.0.23.1
cartpaujmingle-forum1.0.23.2
cartpaujmingle-forum1.0.24
cartpaujmingle-forum1.0.25
cartpaujmingle-forum1.0.26
cartpaujmingle-forum1.0.27
cartpaujmingle-forum1.0.28
cartpaujmingle-forum1.0.28.1
cartpaujmingle-forum1.0.28.2
cartpaujmingle-forum1.0.29
cartpaujmingle-forum1.0.30
cartpaujmingle-forum1.0.31
cartpaujmingle-forum1.0.31.1
cartpaujmingle-forum1.0.31.2
cartpaujmingle-forum1.0.31.3
cartpaujmingle-forum1.0.31.4
cartpaujmingle-forum1.0.32
wordpress wordpresswordpress-

References

CWEs

CWE-89

Verify integrity in audit chain (admin only). AS-IS.