01642 06 11 11 Arrange Call

SQL Injection Vulnerability in Simple URLs WordPress Plugin

CVE-2023-0098 · HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2023-0098

The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.

Learn more about our Wordpress Pen Testing.