AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2014-5182

MEDIUM · CVSS 6 EPSS 2.27%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-08-06 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2014-5182
Severity
MEDIUM
CVSS
6
EPSS
2.27%
WordPress

Original NVD Description

Multiple SQL injection vulnerabilities in the yawpp plugin 1.2 for WordPress allow remote authenticated users with Contributor privileges to execute arbitrary SQL commands via vectors related to (1) admin_functions.php or (2) admin_update.php, as demonstrated by the id parameter in the update action to wp-admin/admin.php.