Vulnerabilities > Easymodal Project

DATE CVE VULNERABILITY TITLE RISK
2017-08-18 CVE-2017-12947 SQL Injection vulnerability in Easymodal Project Easy Modal
classes\controller\admin\modals.php in the Easy Modal plugin before 2.1.0 for WordPress has SQL injection in an untrash action with the id, ids, or modal parameter to wp-admin/admin.php, exploitable by administrators.
network
low complexity
easymodal-project CWE-89
6.5
2017-08-18 CVE-2017-12946 SQL Injection vulnerability in Easymodal Project Easy Modal
classes\controller\admin\modals.php in the Easy Modal plugin before 2.1.0 for WordPress has SQL injection in a delete action with the id, ids, or modal parameter to wp-admin/admin.php, exploitable by administrators.
network
low complexity
easymodal-project CWE-89
6.5