Back to Database
Status published
High
CVE-2017-2195
SQL injection vulnerability in the Multi Feed Reader prior to...
Vulnerability Description
SQL injection vulnerability in the Multi Feed Reader prior to version 2.2.4 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-2195
Credits & Attribution
No credits recorded in the NVD database.
References
More from Eric Teubert
View All →CVE-2025-58204
WordPress Podlove Podcast Publisher Plugin <= 4.2.5 - Open Redirection Vulnerability
Medium
4.7
CVE-2024-53718
WordPress Multi Feed Reader plugin <= 2.2.4 - CSRF to Stored Cross Site Scripting (XSS) vulnerability
High
7.1
CVE-2024-52393
WordPress Podlove Podcast Publisher plugin <= 4.1.15 - Admin+ Remote Code Execution (RCE) vulnerability
Critical
9.1
CVE-2023-46194
WordPress Archivist – Custom Archive Templates Plugin <= 1.7.5 is vulnerable to Cross Site Scripting (XSS)
Medium
5.8
CVE-2023-25490
WordPress Archivist – Custom Archive Templates Plugin <= 1.7.4 is vulnerable to Cross Site Scripting (XSS)
Medium
5.9
Affected Vendor
Eric Teubert
View all reports →Affected Software
Multi Feed Reader
Vulnerable Versions:
prior to version 2.2.4
Timeline
Official Publish:
June 9th, 2017
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.