Beta

Report

SEO Booster <= 3.7 is vulnerable to SQL Injection (SQLi) vulnerability

Administrator
Published
2021-11-14

The SEO Booster WordPress plugin before 3.8 allows for authenticated SQL injection via the "fn_my_ajaxified_dataloader_ajax" AJAX request as the $_REQUEST['order'][0]['dir'] parameter is not properly escaped leading to blind and error-based SQL injections.

CVSS

Score:5.5

Severity:Medium

Version: 3.7

There is a patch available in v3.8 and we strongly recommend you update to this version as soon as possible.