CVE-2014-5183
medium
CVSS v3
—
CVSS v2
6.5
VIR risk
6.5
Description
SQL injection vulnerability in includes/mode-edit.php in the Simple Retail Menus (simple-retail-menus) plugin before 4.1 for WordPress allows remote authenticated editors to execute arbitrary SQL commands via the targetmenu parameter in an edit action to wp-admin/admin.php.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=861170%40simple-retail-menus&old=728969%40simple-retail-menus&sfp_email=&sfph_mail=#file1
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| simple_retail_menus_plugin_project | simple-retail-menus | {"endIncluding":"4.0.1"} | |
| simple_retail_menus_plugin_project | simple-retail-menus | 4.0 | |
References
- http://codevigilant.com/disclosure/wp-plugin-simple-retail-menus-a1-injection
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=861170%40simple-retail-menus&old=728969%40simple-retail-menus&sfp_email=&sfph_mail=#file1
- http://codevigilant.com/disclosure/wp-plugin-simple-retail-menus-a1-injection
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=861170%40simple-retail-menus&old=728969%40simple-retail-menus&sfp_email=&sfph_mail=#file1
CWEs
CWE-89
Verify integrity in audit chain (admin only). AS-IS.