First published: Mon Apr 10 2023(Updated: )
The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg WordPress plugin before 2.7.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
barnraiser AROUNDMe | <2.7.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1425 is a vulnerability in the WordPress CRM Email & Marketing Automation for WordPress | Award Winner — Groundhogg WordPress plugin before 2.7.9.4 that allows SQL injection by high privilege users.
The severity of CVE-2023-1425 is high with a severity value of 7.2.
The Groundhogg WordPress plugin versions up to 2.7.9.4 are affected by CVE-2023-1425.
The SQL injection vulnerability in CVE-2023-1425 can be exploited by high privilege users, such as admins, who can inject malicious SQL statements.
Yes, updating the Groundhogg WordPress plugin to version 2.7.9.4 or higher will fix the SQL injection vulnerability associated with CVE-2023-1425.