Vulnerability CVE-2023-2655


Published: 2024-01-16

Description:
The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

 References:
https://wpscan.com/vulnerability/b3f2d38f-8eeb-45e9-bb58-2957e416e1cd/

Copyright 2026, cxsecurity.com

 

Back to Top