First published: Tue May 30 2023(Updated: )
The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Elementor Website Builder WordPress | <3.12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0329 is a vulnerability in the Elementor Website Builder WordPress plugin before version 3.12.2 that allows SQL injection.
CVE-2023-0329 affects the Elementor Website Builder plugin before version 3.12.2 by not properly sanitizing and escaping the Replace URL parameter in the Tools module, leading to SQL injection.
CVE-2023-0329 has a severity level of high with a severity value of 7.
To fix CVE-2023-0329, you should update the Elementor Website Builder plugin to version 3.12.2 or later.
For more information about CVE-2023-0329, you can refer to the following reference: [https://wpscan.com/vulnerability/a875836d-77f4-4306-b275-2b60efff1493](https://wpscan.com/vulnerability/a875836d-77f4-4306-b275-2b60efff1493)