CVE Database /
CVE-2017-12650
CVE · Critical
CVE-2017-12650 — Loginizer [loginizer] < 1.3.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2017-12650
|
Loginizer [loginizer] < 1.3.6 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Critical
9.8
|
< 1.3.6
|
1.3.6 |
2017-08-07 |
—
|
CVE-2017-12650
The Loginizer plugin before version 1.3.6 contains a blind SQL injection vulnerability caused by unsanitized HTTP header data being passed directly to the lz_selectquery() function and subsequently to $wpdb->get_results(). This flaw allows attackers to execute arbitrary SQL queries through specially crafted headers. Users should upgrade to version 1.3.6 or later to remediate this issue.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings