CVE-2023-5041
Last modified
CVE-2023-5041 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The Track The Click WordPress plugin before 0.3.12 does not properly sanitize query parameters to the stats REST endpoint before using them in a database query, allowing a logged in user with an author role or higher to perform time based blind SQLi attacks on the database.. EPSS estimates a 0.88% chance of exploitation in the next 30 days.
Description
The Track The Click WordPress plugin before 0.3.12 does not properly sanitize query parameters to the stats REST endpoint before using them in a database query, allowing a logged in user with an author role or higher to perform time based blind SQLi attacks on the database.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tracktheclick | Track The Click | < 0.3.12 |
References
- https://wpscan.com/vulnerability/45194442-6eea-4e07-85a5-4a1e2fde3523Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/45194442-6eea-4e07-85a5-4a1e2fde3523Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-5041?
How severe is CVE-2023-5041?
How do I fix CVE-2023-5041?
Are you affected by CVE-2023-5041?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
