CVE-2023-23651: WordPress MainWP Google Analytics Extension Plugin <= 4.0.4 - SQL Injection vulnerability
Published Oct 12, 2023
·Updated
Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP Google Analytics Extension plugin <= 4.0.4 versions.
Affected Software
1 affected component
MainWP Mainwp Google Analytics Extension Wordpress<=4.0.4
Remediation
Information
Update to 4.0.5 or a higher version.
Event History
Oct 12, 2023
CVE Published
via MITRE·11:26 AM
Data Sourced
via MITRE·11:26 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-23651?
CVE-2023-23651 is an SQL Injection (SQLi) vulnerability in the MainWP Google Analytics Extension plugin.
2
What is the severity of CVE-2023-23651?
CVE-2023-23651 has a severity of 8.5, which is considered high.
3
Which version of the MainWP Google Analytics Extension plugin is affected by CVE-2023-23651?
CVE-2023-23651 affects versions up to and including 4.0.4 of the MainWP Google Analytics Extension plugin.
4
How does CVE-2023-23651 impact authentication?
CVE-2023-23651 allows authenticated users with at least subscriber+ role to perform SQL Injection attacks.
5
Is there a fix available for CVE-2023-23651?
Yes, a fix is available for CVE-2023-23651. It is recommended to update to version 4.0.5 or later of the MainWP Google Analytics Extension plugin.