InLinks Plugin for WordPress: Authenticated SQL Injection Vulnerability

InLinks Plugin for WordPress: Authenticated SQL Injection Vulnerability

CVE-2017-16955 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

SQL injection vulnerability in the InLinks plugin through 1.1 for WordPress allows authenticated users to execute arbitrary SQL commands via the "keyword" parameter to /wp-admin/options-general.php?page=inlinks/inlinks.php.

Learn more about our Wordpress Pen Testing.