WordPress Perfect Survey <1.5.2 - SQL Injection
Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.
PoC 已收录perfect_survey
CVSS9.8EPSS 83.6%