PT-2023-16119 · WordPress · Wp Google Review Slider

Lana Codes

·

Published

2023-02-13

·

Updated

2023-02-15

·

CVE-2023-0259

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Google Review Slider versions prior to 11.8
Description The issue arises from improper sanitization and escaping of a parameter before its use in a SQL statement, resulting in a SQL injection that can be exploited by users with a role as low as subscriber.
Recommendations For versions prior to 11.8, update to version 11.8 or later to resolve the issue.

Exploit

Fix

Related Identifiers

CVE-2023-0259

Affected Products

Wp Google Review Slider