CVE-2023-0487: My Sticky Elements < 2.0.9 - Admin+ SQLi
Published Feb 27, 2023
·Updated
The My Sticky Elements WordPress plugin before 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement when deleting messages, leading to a SQL injection exploitable by high privilege users such as admin
Affected Software
1 affected component
Premio My Sticky Elements Wordpress<2.0.9
Event History
Feb 27, 2023
CVE Published
via MITRE·03:24 PM
Data Sourced
via MITRE·03:24 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of the My Sticky Elements WordPress plugin?
The vulnerability ID of the My Sticky Elements WordPress plugin is CVE-2023-0487.
2
What is the severity level of CVE-2023-0487?
The severity level of CVE-2023-0487 is high.
3
How does CVE-2023-0487 affect the My Sticky Elements WordPress plugin?
CVE-2023-0487 affects the My Sticky Elements WordPress plugin by allowing high privilege users, such as admins, to exploit a SQL injection vulnerability.
4
How can high privilege users exploit CVE-2023-0487?
High privilege users can exploit CVE-2023-0487 by manipulating a parameter to execute unauthorized SQL statements.
5
How can I fix the CVE-2023-0487 vulnerability in the My Sticky Elements WordPress plugin?
To fix the CVE-2023-0487 vulnerability in the My Sticky Elements WordPress plugin, update to version 2.0.9 or above.