UBUNTU-CVE-2017-16510
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-16510
Summary:
Details: WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.
References: https://ubuntu.com/security/CVE-2017-16510, https://wpvulndb.com/vulnerabilities/8941, https://github.com/WordPress/WordPress/commit/a2693fd8602e3263b5925b9d799ddd577202167d, https://blog.ircmaxell.com/2017/10/disclosure-wordpress-wpdb-sql-injection-technical.html, https://codex.wordpress.org/Version_4.8.3, https://wordpress.org/news/2017/10/wordpress-4-8-3-security-release/, https://www.cve.org/CVERecord?id=CVE-2017-16510
Affected packages
Package
Name: wordpress
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1ubuntu1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
