CVE-2023-1730: SupportCandy < 3.1.5 - Unauthenticated SQLi
Published May 2, 2023
·Updated
The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks
Affected Software
1 affected component
SupportCandy SupportCandy WordPress<3.1.5
Event History
May 2, 2023
CVE Published
via MITRE·07:05 AM
Data Sourced
via MITRE·07:05 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-1730?
The severity of CVE-2023-1730 is critical.
2
How does CVE-2023-1730 affect SupportCandy WordPress plugin?
CVE-2023-1730 affects SupportCandy WordPress plugin versions up to and including 3.1.5.
3
What is the vulnerability type of CVE-2023-1730?
The vulnerability type of CVE-2023-1730 is SQL injection.
4
How can an attacker exploit CVE-2023-1730?
An unauthenticated attacker can exploit CVE-2023-1730 by performing SQL injection attacks.
5
Is there a fix available for CVE-2023-1730?
Yes, updating to SupportCandy WordPress plugin version 3.1.6 or later fixes CVE-2023-1730.