vulnerability

WordPress Plugin: wp-advanced-search: CVE-2020-12104: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
Apr 28, 2020
Added
May 15, 2025
Modified
May 15, 2025

Description

The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation.

Solution

wp-advanced-search-plugin-cve-2020-12104
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.