CVE-2017-5611SQL Injection in Wordpress

CWE-89SQL Injection9 documents7 sources
Severity
9.8CRITICALNVD
EPSS
12.4%
top 6.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 30
Latest updateMay 13

Description

SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

Debianwordpress/wordpress< 4.7.2+dfsg-1+3
NVDoracle/data_integrator11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0+2

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-r745-4v47-m5c7: SQL injection vulnerability in wp-includes/class-wp-query2022-05-13
OSV
CVE-2017-5611: SQL injection vulnerability in wp-includes/class-wp-query2017-01-30
CVEList
CVE-2017-5611: SQL injection vulnerability in wp-includes/class-wp-query2017-01-30
VulnCheck
WordPress wordpress Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2017

📋Vendor Advisories

1
Debian
CVE-2017-5611: wordpress - SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in Wor...2017

💬Community

3
Bugzilla
CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2 [epel-all]2017-01-27
Bugzilla
CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2 [fedora-all]2017-01-27
Bugzilla
CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.22017-01-27
CVE-2017-5611 — SQL Injection in Wordpress | cvebase