CVE-2020-12104: Internet-Formation Wp-Advanced-Search

High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.

The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation.

Affected products

Published 2020-05-05. Last modified 2026-06-17.