The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2023-05-02T07:05:01.073Z
Updated: 2024-08-02T05:57:24.977Z
Reserved: 2023-03-30T14:55:03.802Z
Link: CVE-2023-1730
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-05-02T08:15:10.267
Modified: 2024-11-21T07:39:47.050
Link: CVE-2023-1730
Redhat
No data.