Beta

Report

Google Document Embedder <= 2.5.14 is vulnerable to SQL Injection

Unauthenticated
Published
2014-11-24

SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote attackers to execute arbitrary SQL commands via the gpid parameter.

CVSS

Score:9.8

Severity:Critical

Version: 2.5.14

There is a patch available in v2.5.15 and we strongly recommend you update to this version as soon as possible.