Description
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.
Remediation
References
Related Vulnerabilities
WordPress Plugin Social Media Share Buttons & Social Sharing Icons Cross-Site Scripting (1.1.1.11)
WordPress Plugin Woosaleskit Bar Cross-Site Scripting (1.0.0)
MySQL CVE-2018-3058 Vulnerability (CVE-2018-3058)
WordPress Plugin WP Smart Import: Import any XML File to WordPress Cross-Site Scripting (1.0.2)
WordPress Plugin Booking Calendar Contact Form Multiple Vulnerabilities (1.0.23)