CVE-2020-12104: Internet-Formation Wp-Advanced-Search
High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.
The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation.
Affected products
- Internet-Formation Wp-Advanced-Search: before 3.3.7 (fixed in 3.3.7)
Published 2020-05-05. Last modified 2026-06-17.