Date published: 2017-09-14T09:29:00.420-04:00
Date last modified: 2017-09-18T12:28:37.393-04:00
CVSS Score: 5.0
Principal attack vector: NETWORK
Reference URL: http://www.securityfocus.com/bid/96890
Summary: Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn’t check that the user is authorized before injecting new contacts into the wp_contact table.