CVE-2023-5108
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Dec 4, 2023
Updated: Dec 7, 2023
CWE ID 787
Summary
CVE-2023-5108 is a vulnerability affecting the Easy Newsletter Signups plugin for WordPress. This issue allows SQL injection attacks for users with high privileges, such as admins. The plugin fails to adequately sanitize and escape a specific input parameter, making it susceptible to manipulation in SQL statements. This flaw can potentially enable attackers to gain unauthorized access to sensitive data or even take control of the affected WordPress site.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share