The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Mar 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published: 2023-02-13T14:32:15.988Z
Updated: 2025-03-21T19:29:51.689Z
Reserved: 2023-01-06T10:28:04.930Z
Link: CVE-2023-0098

Updated: 2024-08-02T05:02:43.163Z

Status : Modified
Published: 2023-02-13T15:15:20.577
Modified: 2025-03-21T20:15:14.540
Link: CVE-2023-0098

No data.