CyberRota Analysis
AI-GeneratedThe Dinatur WordPress plugin versions up to 1.18 are vulnerable to SQL injection due to inadequate sanitization and escaping of user input, enabling unauthenticated users to execute malicious SQL queries. Additionally, the plugin allows unauthorized database table truncation, which can lead to data loss for any unauthenticated visitor. WordPress site administrators using this plugin should prioritize immediate updates or mitigations to protect against these critical vulnerabilities.
Original NVD Description
The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. The same handler also performs a database table truncation without any authorization check, allowing any unauthenticated visitor to wipe the Dinatur WordPress plugin through 1.18's data.