First published: Mon Feb 27 2023(Updated: )
The GigPress WordPress plugin through 2.3.28 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tri Gigpress | <=2.3.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0381 has been classified with a medium severity level due to its potential for SQL Injection attacks.
To fix CVE-2023-0381, upgrade the GigPress WordPress plugin to version 2.3.29 or later.
CVE-2023-0381 affects any authenticated users of GigPress version 2.3.28 or earlier, including subscribers.
CVE-2023-0381 is an SQL Injection vulnerability resulting from improper validation and escaping of shortcode attributes.
CVE-2023-0381 cannot be exploited remotely as it requires authentication to perform SQL Injection attacks.