CVE-2016-20073
Answer My Question 1.3 Plugin WordPress SQL Injection via modal.php
CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th
Answer My Question 1.3 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' POST parameter. Attackers can submit crafted SQL statements to the modal.php endpoint to extract sensitive database information including WordPress terms and configuration data.
| CWE | CWE-89 |
| Vendor | mattkaye |
| Product | answer my question |
| Published | Jun 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for mattkaye answer my question
Be the first to know when new high vulnerabilities affecting mattkaye answer my question are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
mattkaye / Answer My Question
1.3
References
Credits
Lenon Leite