[Plugin: Ninja Announcements] SQL injection hole
-
The way that the plugin handles deletes/deactivations/activations has two pretty major security issues. First of all, it allows anyone to fire off deletion/deactivation/activation without being logged in. But even worse than that the way the sql calls are being made leave it wide open to a SQL injection attack. So anyone could wipe out or insert garbage into a WordPress site with this plugin loaded. I’d be happy to chat more about this if you need more specifics.
Viewing 2 replies - 1 through 2 (of 2 total)
Viewing 2 replies - 1 through 2 (of 2 total)
The topic ‘[Plugin: Ninja Announcements] SQL injection hole’ is closed to new replies.