Vulnerability Description
Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_class.php; or the id parameter to (2) pages/content_timeline_edit.php or (3) pages/content_timeline_index.php.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Shindiristudio | Content Timeline | 4.4.2 |
Related Weaknesses (CWE)
References
- https://wpvulndb.com/vulnerabilities/8921ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/42794/ExploitThird Party AdvisoryVDB Entry
- https://wpvulndb.com/vulnerabilities/8921ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/42794/ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2017-14507?
CVE-2017-14507 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_cl...
How severe is CVE-2017-14507?
CVE-2017-14507 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-14507?
Check the references section above for vendor advisories and patch information. Affected products include: Shindiristudio Content Timeline.