CVE-2017-12947: Easymodal Project Easy Modal
High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.
classes\controller\admin\modals.php in the Easy Modal plugin before 2.1.0 for WordPress has SQL injection in an untrash action with the id, ids, or modal parameter to wp-admin/admin.php, exploitable by administrators.
Affected products
- Easymodal Project Easy Modal: up to and including 2.0.17
Published 2017-08-18. Last modified 2026-06-17.