High severity8.8NVD Advisory· Published Jan 23, 2017· Updated May 13, 2026
CVE-2016-0769
CVE-2016-0769
Description
Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote administrators to execute arbitrary SQL commands via the delid parameter or remote authenticated users to execute arbitrary SQL commands via the (2) view, (3) mark, or (4) change parameter.
Affected products
1- cpe:2.3:a:elfden:eshop_plugin:6.3.14:*:*:*:*:wordpress:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.openwall.com/lists/oss-security/2016/02/02/3nvdExploitThird Party Advisory
- www.vapid.dhs.org/advisory.phpnvdExploitThird Party Advisory
- www.securityfocus.com/bid/82347nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.