CVE · Critical

CVE-2017-12650 — Loginizer [loginizer] < 1.3.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2017-12650 Loginizer [loginizer] < 1.3.6 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 1.3.6 1.3.6 2017-08-07

CVE-2017-12650

The Loginizer plugin before version 1.3.6 contains a blind SQL injection vulnerability caused by unsanitized HTTP header data being passed directly to the lz_selectquery() function and subsequently to $wpdb->get_results(). This flaw allows attackers to execute arbitrary SQL queries through specially crafted headers. Users should upgrade to version 1.3.6 or later to remediate this issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.