CVE-2017-16510

NameCVE-2017-16510
DescriptionWordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1160-1, DSA-4090-1
NVD severityhigh (attack range: remote)
Debian Bugs880528

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
wordpress (PTS)jessie4.1+dfsg-1+deb8u17fixed
jessie (security)4.1+dfsg-1+deb8u18fixed
stretch (security), stretch4.7.5+dfsg-2+deb9u4fixed
buster, sid4.9.8+dfsg1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
wordpresssource(unstable)4.8.3+dfsg-1high880528
wordpresssourcejessie4.1+dfsg-1+deb8u16highDSA-4090-1
wordpresssourcestretch4.7.5+dfsg-2+deb9u2highDSA-4090-1
wordpresssourcewheezy3.6.1+dfsg-1~deb7u18highDLA-1160-1

Notes

https://wpvulndb.com/vulnerabilities/8941
https://github.com/WordPress/WordPress/commit/a2693fd8602e3263b5925b9d799ddd577202167d
https://blog.ircmaxell.com/2017/10/disclosure-wordpress-wpdb-sql-injection-technical.html

Search for package or bug name: Reporting problems