CVE-2016-20063
Single Personal Message 1.0.3 WordPress Plugin SQL Injection
CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th
Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries by injecting malicious code through the message parameter. Attackers can access the admin interface and supply crafted SQL statements in the message parameter to extract sensitive database information including user credentials and site configuration data.
| CWE | CWE-89 |
| Vendor | md. shamim shahnewaz |
| Product | single personal message |
| Published | Jun 9, 2026 |
| Last Updated | Jun 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for md. shamim shahnewaz single personal message
Be the first to know when new high vulnerabilities affecting md. shamim shahnewaz single personal message are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
Md. Shamim Shahnewaz / Single Personal Message
1.0.3
References
exploit-db.com: https://www.exploit-db.com/exploits/40870 wordpress.org: https://wordpress.org/plugins/simple-personal-message/ lenonleite.com.br: http://lenonleite.com.br/ target: http://target/wp-admin/admin.php?page=simple-personal-message-outbox&action=view&message=0%20UNION%20SELECT%201,2.3,name,5,slug,7,8,9,10,11,12%20FROM%20wp_terms%20WHERE%20term_id=1 vulncheck.com: https://www.vulncheck.com/advisories/single-personal-message-wordpress-plugin-sql-injection
Credits
Lenon Leite