WordPress plugin "Multi Feed Reader" vulnerable to SQL injection


The WordPress plugin "Multi Feed Reader" contains an SQL injection vulnerability (CWE-89).

Yuji Tounai of NTT Communications Corporation reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 6.3 (Medium) [IPA Score]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: Low
  • Integrity Impact: Low
  • Availability Impact: Low
CVSS V2 Severity:
Base Metrics 6.5 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Low
  • Authentication: Single Instance
  • Confidentiality Impact: Partial
  • Integrity Impact: Partial
  • Availability Impact: Partial
Affected Products

Eric Teubert
  • Multi Feed Reader prior to version 2.2.4


An attacker who can access the product may execute an arbitrary SQL command. Information stored in the database may be obtained or altered by an attacker.

[Update the plugin]
Update the plugin according to the information provided by the developer.
Vendor Information

Eric Teubert
CWE (What is CWE?)

  1. SQL Injection(CWE-89) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2017-2195

  1. JVN : JVN#98617234
  2. National Vulnerability Database (NVD) : CVE-2017-2195
Revision History

  • [2017/06/06]
      Web page was published
      References : Content was added