4 results (0.006 seconds)

CVSS: 8.5EPSS: 0%CPEs: 1EXPL: 0

25 Sep 2024 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPManageNinja LLC Fluent Support allows SQL Injection.This issue affects Fluent Support: from n/a through 1.8.0. The Fluent Support plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscri... • https://patchstack.com/database/vulnerability/fluent-support/wordpress-fluent-support-plugin-1-8-0-sql-injection-vulnerability?_s_id=cve • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

25 Sep 2024 — Missing Authorization vulnerability in WPManageNinja LLC Fluent Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Support: from n/a through 1.8.0. The Fluent Support plugin for WordPress is vulnerable to unauthorized email verification due to insufficient validation on the sendSignupEmailVerificationHtml ()function in versions up to, and including, 1.8.0. This makes it possible for unauthenticated attackers to verify emails that do not belong to themse... • https://patchstack.com/database/vulnerability/fluent-support/wordpress-fluent-support-plugin-1-8-0-broken-access-control-on-email-verification-vulnerability?_s_id=cve • CWE-862: Missing Authorization •

CVSS: 8.3EPSS: 0%CPEs: 1EXPL: 0

27 Dec 2023 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPManageNinja LLC Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin.This issue affects Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin: from n/a through 1.7.6. Neutralización incorrecta de elementos especiales utilizados en una vulnerabilidad de comando SQL ('inyección SQL') en WPManageNinja LLC Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugi... • https://patchstack.com/database/vulnerability/fluent-support/wordpress-fluent-support-plugin-1-7-6-sql-injection-vulnerability?_s_id=cve • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 8.3EPSS: 0%CPEs: 1EXPL: 1

02 Aug 2022 — The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection vulnerability exploitable by high privilege users El plugin Fluent Support de WordPress versiones anteriores a 1.5.8, no sanea, comprueba y escapa de varios parámetros antes de usarlos en una sentencia SQL, conllevando a una vulnerabilidad de inyección SQL explotable por usuarios con altos privilegios The Fluent Support plugin ... • https://wpscan.com/vulnerability/062599ce-c630-487e-bb43-c3b27a62b9ec • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •