CVE-2014-8810: Wpsymposiumpro Wp Symposium

Medium severity, CVSS 6.5. EPSS: 3.6% chance of exploitation in the next 30 days.

SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tray parameter in a getMailMessage action.

Affected products

Published 2014-12-24. Last modified 2026-06-17.