SQL Injection Vulnerabilities in Double Opt-In for Download Plugin for WordPress

SQL Injection Vulnerabilities in Double Opt-In for Download Plugin for WordPress

CVE-2015-7517 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

Multiple SQL injection vulnerabilities in the Double Opt-In for Download plugin before 2.0.9 for WordPress allow remote attackers to execute arbitrary SQL commands via the ver parameter to (1) class-doifd-download.php or (2) class-doifd-landing-page.php in public/includes/.

Learn more about our Wordpress Pen Testing.