CVE-2017-16510
moderate-risk
Published 2017-11-02
WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.
Do I need to act?
~
4.2% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
+
Fix available
Upgrade to: a2693fd8602e3263b5925b9d799ddd577202167d
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (1)
Affected Vendors
References (16)
Third Party Advisory
http://www.securityfocus.com/bid/101638
Issue Tracking
https://codex.wordpress.org/Version_4.8.3
Issue Tracking
https://wpvulndb.com/vulnerabilities/8941
Third Party Advisory
http://www.securityfocus.com/bid/101638
Issue Tracking
https://codex.wordpress.org/Version_4.8.3
Issue Tracking
https://wpvulndb.com/vulnerabilities/8941
44
/ 100
moderate-risk
Severity
32/34 · Critical
Exploitability
7/34 · Low
Exposure
5/34 · Minimal