NA

CVE-2023-0630

Published: 20/03/2023 Updated: 07/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Slimstat Analytics WordPress plugin prior to 4.9.3.3 does not prevent subscribers from rendering shortcodes that concatenates attributes directly into an SQL query.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wp-slimstat slimstat analytics

Github Repositories

CVE-2023-0630 - Slimstat Analytics < 4.9.3.3 - Subscriber+ SQL Injection

CVE-2023-0630 CVE-2023-0630 - Slimstat Analytics &lt; 4933 - Subscriber+ SQL Injection Must Have sqlmap installed &amp; a valid username &amp; password with subscriber+ Usage usage: CVE-2023-0630py [-h] -w URL -u USERNAME -p PASSWORD options: -h, --help show this help message and exit -w URL, --url URL URL of the WordPress site -u USERNAME,