Date published: 2017-09-14T09:29:00.467-04:00
Date last modified: 2017-09-18T12:28:44.847-04:00
CVSS Score: 5.0
Principal attack vector: NETWORK
Reference URL: http://www.securityfocus.com/bid/96890
Summary: Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn’t check that the user is authorized before injecting new contacts into the wp_contact table.