Vulnerability Description
Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a dex_reservations_calendar_load2 action or (2) dex_item parameter in a dex_reservations_check_posted_data action in a request to the default URI.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cp Reservation Calender Project | Cp Reservation Calender | <= 1.1.6 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset/1104099/cp-reservation-calendar
- https://wordpress.org/plugins/cp-reservation-calendar/changelog/Patch
- https://wpvulndb.com/vulnerabilities/8193
- https://www.exploit-db.com/exploits/38187/Exploit
- https://plugins.trac.wordpress.org/changeset/1104099/cp-reservation-calendar
- https://wordpress.org/plugins/cp-reservation-calendar/changelog/Patch
- https://wpvulndb.com/vulnerabilities/8193
- https://www.exploit-db.com/exploits/38187/Exploit
FAQ
What is CVE-2015-7235?
CVE-2015-7235 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) id ...
How severe is CVE-2015-7235?
CVE-2015-7235 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-7235?
Check the references section above for vendor advisories and patch information. Affected products include: Cp Reservation Calender Project Cp Reservation Calender.