Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by exploiting the unescaped 'idsignup' POST parameter. Attackers can send crafted requests to the admin-ajax.php endpoint with malicious SQL payloads in the 'idsignup' parameter to read arbitrary data from the database.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by exploiting the unescaped 'idsignup' POST parameter. Attackers can send crafted requests to the admin-ajax.php endpoint with malicious SQL payloads in the 'idsignup' parameter to read arbitrary data from the database. | |
| Title | Wow Viral Signups 2.1 WordPress Plugin SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-09T13:09:18.331Z
Reserved: 2026-06-08T11:46:10.924Z
Link: CVE-2017-20245
Updated: 2026-06-09T13:09:15.080Z
Status : Received
Published: 2026-06-09T13:16:34.270
Modified: 2026-06-09T13:16:34.270
Link: CVE-2017-20245
No data.
OpenCVE Enrichment
Updated: 2026-06-09T13:30:04Z