CVE-2023-2111: HollerBox < 2.1.4 - Admin+ SQL Injection
The Fast & Effective Popups & Lead-Generation for WordPress plugin before 2.1.4 concatenates user input into an SQL query without escaping it first in the plugin's report API endpoint, which could allow administrators in multi-site configuration to leak sensitive information from the site's database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2111?
The severity of CVE-2023-2111 is medium with a severity value of 4.9.
How does CVE-2023-2111 affect the Fast & Effective Popups & Lead-Generation for WordPress plugin?
CVE-2023-2111 affects the Fast & Effective Popups & Lead-Generation for WordPress plugin before version 2.1.4.
What does CVE-2023-2111 allow administrators in multi-site configuration to do?
CVE-2023-2111 allows administrators in multi-site configuration to leak sensitive information from the site's database.
Is there a fix available for CVE-2023-2111?
Yes, upgrading the Fast & Effective Popups & Lead-Generation for WordPress plugin to version 2.1.4 or higher fixes CVE-2023-2111.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-2111?
The Common Weakness Enumeration (CWE) ID for CVE-2023-2111 is 89.