CVE-2009-4748
Summary
| CVE | CVE-2009-4748 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-03-26 20:30:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the parentID parameter in an act_OrderCategories action to wp-admin/post-new.php. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Andrew Charlton | My Category Order | 2.6.1 | All | All | All |
| Application | Andrew Charlton | My Category Order | 2.6.1a | All | All | All |
| Application | Andrew Charlton | My Category Order | 2.7 | All | All | All |
| Application | Andrew Charlton | My Category Order | 2.7.1 | All | All | All |
| Application | Andrew Charlton | My Category Order | All | All | All | All |
| Application | Wordpress | Wordpress | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WordPress My Category Order Plugin 'parentID' Parameter SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| WordPress Plugin My Category Order <= 2.8 SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Files ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.