CVE-2023-0579
The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscribers to perform SQL Injection attacks.
- Affected products
- Yarpp
- Yarpp Yet Another Related Posts Plugin
- < 5.30.3
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 0.9% (58th percentile)
- Weakness
- CWE-89
- NVD status
- Analyzed
- Published
- 2023-08-16
CVE-2023-0579 at NVD
1 known exploit for CVE-2023-0579
Proof-of-concept code and exploit modules indexed by Sploitus