Vulnerability CVE-2023-0098


Published: 2023-02-13

Description:
The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.

Type:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

 References:
https://wpscan.com/vulnerability/db0b3275-40df-404e-aa8d-53558f0122d8

Copyright 2026, cxsecurity.com

 

Back to Top