← Back to CVE List
CVE-2018-16159
The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request.
> MITRE Terms of Use apply – see LICENSE‑MITRE.txt