CVE-2013-0735: Cartpauj Mingle-Forum
High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.
Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to execute arbitrary SQL commands via the id parameter in a viewtopic (1) remove_post, (2) sticky, or (3) closed action or (4) thread parameter in a postreply action to index.php.
Affected products
- Cartpauj Mingle-Forum: up to and including 1.0.33; version 1.0.00 only; version 1.0.01 only; version 1.0.02 only; version 1.0.03 only; version 1.0.04 only; …
Published 2014-04-02. Last modified 2026-06-16.