CVE-2023-0261
The WP TripAdvisor Review Slider WordPress plugin before 10.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.
- Affected products
- Wp Tripadvisor Review Slider
- Ljapps Wp Tripadvisor Review Slider
- < 10.8
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 4.4% (90th percentile)
- NVD status
- Modified
- Published
- 2023-02-13
CVE-2023-0261 at NVD
1 known exploit for CVE-2023-0261
Proof-of-concept code and exploit modules indexed by Sploitus