CVE-2023-52133
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Dec 31, 2023
Updated: Jan 5, 2024
CWE ID 89
Summary
CVE-2023-52133 is a newly disclosed SQL Injection vulnerability that affects the Most and Least Read Posts Widget, version 2.5.16 and prior. The weakness lies in the widget's handling of user input in SQL commands, which could result in unauthorized access to sensitive data or even complete system takeover. Attackers can exploit this flaw by injecting malicious SQL code into the widget's input fields, leading to potential data breaches. It is crucial for users to update their widgets to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share