CVE-2017-16510
WordPress Core < 4.8.3 - SQL Injection due to Double Prepare approach
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.
WordPress en versiones anteriores a la 4.8.3 se ve afectado por un problema en el que $wpdb->prepare() puede crear consultas inseguras e inesperadas que podrÃan provocar una inyección SQL (SQLi) en plugins y temas, tal y como se ve en el enfoque "double prepare". Esta es una vulnerabilidad diferente a CVE-2017-14723.
Several vulnerabilities were discovered in Wordpress, a web blogging tool. They allowed remote attackers to perform SQL injections and various Cross-Side Scripting (XSS) and Server-Side Request Forgery (SSRF) attacks, as well as bypass some access restrictions.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-10-31 CVE Published
- 2017-11-02 CVE Reserved
- 2024-08-05 CVE Updated
- 2025-06-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/101638 | Third Party Advisory | |
https://blog.ircmaxell.com/2017/10/disclosure-wordpress-wpdb-sql-injection-technical.html | Issue Tracking | |
https://lists.debian.org/debian-lts-announce/2017/11/msg00003.html | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/WordPress/WordPress/commit/a2693fd8602e3263b5925b9d799ddd577202167d | 2018-02-04 |
URL | Date | SRC |
---|---|---|
https://codex.wordpress.org/Version_4.8.3 | 2018-02-04 | |
https://wordpress.org/news/2017/10/wordpress-4-8-3-security-release | 2018-02-04 | |
https://wpvulndb.com/vulnerabilities/8941 | 2018-02-04 | |
https://www.debian.org/security/2018/dsa-4090 | 2018-02-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | <= 4.8.2 Search vendor "Wordpress" for product "Wordpress" and version " <= 4.8.2" | - |
Affected
|