vulnerability

WordPress Plugin: ultimate-product-catalogue: CVE-2017-12199: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Severity
7
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Aug 1, 2017
Added
May 15, 2025
Modified
Jun 24, 2025

Description

The Etoile Ultimate Product Catalog plugin 4.2.22 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogue_update_order list-item, video_update_order video-item, image_update_order list-item, tag_group_update_order list_item, category_products_update_order category-product-item, custom_fields_update_order field-item, categories_update_order category-item, subcategories_update_order subcategory-item, and tags_update_order tag-list-item.

Solution

ultimate-product-catalogue-plugin-cve-2017-12199
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.