Description
The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL statement, leading to a SQL injection exploitable by users with relatively low privilege on the site, like subscribers.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-34367 | The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL statement, leading to a SQL injection exploitable by users with relatively low privilege on the site, like subscribers. |
References
History
Tue, 10 Jun 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kaizencoders
Kaizencoders short Url |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:kaizencoders:short_url:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Kaizencoders
Kaizencoders short Url |
Mon, 09 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 06 Jun 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL statement, leading to a SQL injection exploitable by users with relatively low privilege on the site, like subscribers. | |
| Title | Short URL <= 1.6.8 - Subscriber+ SQLi | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-06-09T19:45:35.897Z
Reserved: 2023-05-26T19:48:42.220Z
Link: CVE-2023-2921
Updated: 2025-06-09T19:26:40.426Z
Status : Analyzed
Published: 2025-06-06T06:15:30.597
Modified: 2025-06-10T19:31:20.783
Link: CVE-2023-2921
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD