CVE-2023-6620
CVSS 3.1 Score 7.2 of 10 (high)
Attack Complexity low
Confidentiality high
Integrity high
Availability high
Privileges Required high
Scope unchanged
Details
Published Jan 15, 2024
Updated: Jan 19, 2024
CWE ID 89
Summary
CVE-2023-6620 is a new SQL injection vulnerability affecting the POST SMTP Mailer plugin for WordPress. Before version 2.8.7, the plugin failed to properly sanitize and escape certain parameters used in SQL statements. An attacker with high privilege access, such as an admin, can exploit this flaw to inject malicious SQL code and potentially take control of the WordPress database or site. This vulnerability poses a serious risk and should be addressed by updating to the latest plugin version as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Wpexperts Post Smtp Mailer
Affected Vendors
- WP Experts