Unrated severityNVD Advisory· Published Nov 2, 2015· Updated May 6, 2026
CVE-2015-5308
CVE-2015-5308
Description
Multiple SQL injection vulnerabilities in cs_admin_users.php in the wp-championship plugin 5.8 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) user, (2) isadmin, (3) mail service, (4) mailresceipt, (5) stellv, (6) champtipp, (7) tippgroup, or (8) userid parameter.
Affected products
1- cpe:2.3:a:wp-championship_project:wp-championship:5.8:*:*:*:*:wordpress:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.vapid.dhs.org/advisory.phpnvdExploit
- wpvulndb.com/vulnerabilities/8221nvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.