VYPR
Unrated severityNVD Advisory· Published Aug 6, 2014· Updated May 6, 2026

CVE-2014-5182

CVE-2014-5182

Description

Multiple SQL injection vulnerabilities in the yawpp plugin 1.2 for WordPress allow remote authenticated users with Contributor privileges to execute arbitrary SQL commands via vectors related to (1) admin_functions.php or (2) admin_update.php, as demonstrated by the id parameter in the update action to wp-admin/admin.php.

Affected products

1
  • cpe:2.3:a:ostenta:yawpp:1.2:*:*:*:*:wordpress:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.