The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by adminstrators.
This Cyber News was published on www.tenable.com. Publication date: Tue, 19 Mar 2024 21:56:03 +0000