CVE-2023-5434
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Oct 31, 2023
Updated: Nov 7, 2023
Summary
CVE-2023-5434 is a vulnerability affecting the Superb slideshow gallery plugin for WordPress. The issue, present in versions up to 13.1, allows authenticated attackers with subscriber-level permissions or higher to execute SQL Injections through the plugin's shortcode. This is due to insufficient escaping on user-supplied parameters and a lack of preparation of existing SQL queries. The vulnerability grants attackers the ability to append additional queries, which can be exploited to extract sensitive data from the database.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share