CVE-2023-0381: GigPress <= 2.3.28 - Subscriber+ SQLi
The GigPress WordPress plugin through 2.3.28 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0381?
CVE-2023-0381 has been classified with a medium severity level due to its potential for SQL Injection attacks.
How do I fix CVE-2023-0381?
To fix CVE-2023-0381, upgrade the GigPress WordPress plugin to version 2.3.29 or later.
Who is affected by CVE-2023-0381?
CVE-2023-0381 affects any authenticated users of GigPress version 2.3.28 or earlier, including subscribers.
What type of vulnerability is CVE-2023-0381?
CVE-2023-0381 is an SQL Injection vulnerability resulting from improper validation and escaping of shortcode attributes.
Can CVE-2023-0381 be exploited remotely?
CVE-2023-0381 cannot be exploited remotely as it requires authentication to perform SQL Injection attacks.