Vulnerability CVE-2023-2719


Published: 2023-06-19

Description:
The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in the REST API before using it in an SQL statement, leading to an SQL Injection exploitable by users with a role as low as Subscriber.

Type:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

 References:
https://wpscan.com/vulnerability/d9f6f4e7-a237-49c0-aba0-2934ab019e35

Copyright 2026, cxsecurity.com

 

Back to Top