CVE-2012-5327

medium
Published 2012-10-08 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
6.5

Description

Multiple SQL injection vulnerabilities in fs-admin/fs-admin.php in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) delete_usrgrp[] parameter in a delete_usergroups action, (2) usergroup parameter in an add_user_togroup action, or (3) add_forum_group_id parameter in an add_forum_submit action.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
cartpaujmingle-forum{"endIncluding":"1.0.32.1"}
cartpaujmingle-forum1.0.00
cartpaujmingle-forum1.0.01
cartpaujmingle-forum1.0.02
cartpaujmingle-forum1.0.03
cartpaujmingle-forum1.0.04
cartpaujmingle-forum1.0.05
cartpaujmingle-forum1.0.06
cartpaujmingle-forum1.0.07
cartpaujmingle-forum1.0.08
cartpaujmingle-forum1.0.09
cartpaujmingle-forum1.0.10
cartpaujmingle-forum1.0.11
cartpaujmingle-forum1.0.12
cartpaujmingle-forum1.0.13
cartpaujmingle-forum1.0.14
cartpaujmingle-forum1.0.15
cartpaujmingle-forum1.0.16
cartpaujmingle-forum1.0.17
cartpaujmingle-forum1.0.18
cartpaujmingle-forum1.0.19
cartpaujmingle-forum1.0.20
cartpaujmingle-forum1.0.21
cartpaujmingle-forum1.0.21.1
cartpaujmingle-forum1.0.22
cartpaujmingle-forum1.0.23
cartpaujmingle-forum1.0.23.1
cartpaujmingle-forum1.0.23.2
cartpaujmingle-forum1.0.24
cartpaujmingle-forum1.0.25
cartpaujmingle-forum1.0.26
cartpaujmingle-forum1.0.27
cartpaujmingle-forum1.0.28
cartpaujmingle-forum1.0.28.1
cartpaujmingle-forum1.0.28.2
cartpaujmingle-forum1.0.29
cartpaujmingle-forum1.0.30
cartpaujmingle-forum1.0.31
cartpaujmingle-forum1.0.31.1
cartpaujmingle-forum1.0.31.2
cartpaujmingle-forum1.0.31.3
cartpaujmingle-forum1.0.31.4
cartpaujmingle-forum1.0.32
wordpress wordpresswordpress-

References

CWEs

CWE-89

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.