Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(no matching packages found)
created 2 hours ago Activity log
  • Created & dismissed (no matching packages found) suggestion
WP Ultimate CSV Importer < 9.0 - Admin+ SQLi via AIOSEO Import Fields

The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.

References

Affected products

WP Ultimate CSV Importer
  • <9.0