8.8
CVE-2023-0234
- EPSS 6.67%
- Veröffentlicht 06.02.2023 20:15:14
- Zuletzt bearbeitet 25.03.2025 19:15:40
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
SiteGround Security <= 1.3.0 - Authenticated (Administrator+) SQL Injection
The SiteGround Security WordPress plugin before 1.3.1 does not properly sanitize user input before using it in an SQL query, leading to an authenticated SQL injection issue.
Mögliche Gegenmaßnahme
Security Optimizer – The All-In-One Protection Plugin: Update to version 1.3.1, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Security Optimizer – The All-In-One Protection Plugin
Version
*-1.3.0
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siteground ≫ Siteground Security SwPlatformwordpress Version < 1.3.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.67% | 0.91 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|