CVE-2023-0259
The WP Google Review Slider WordPress plugin before 11.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.
- Affected products
- Wp Google Review Slider
- Ljapps Wp Google Review Slider
- < 11.8
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 0.9% (58th percentile)
- NVD status
- Modified
- Published
- 2023-02-13
CVE-2023-0259 at NVD
1 known exploit for CVE-2023-0259
Proof-of-concept code and exploit modules indexed by Sploitus