CVE-2023-0260
The WP Review Slider WordPress plugin before 12.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.
- Affected products
- Wp Review Slider
- Ljapps Wp Review Slider
- < 12.2
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 0.9% (58th percentile)
- NVD status
- Modified
- Published
- 2023-02-13
CVE-2023-0260 at NVD
1 known exploit for CVE-2023-0260
Proof-of-concept code and exploit modules indexed by Sploitus