First published: Thu Oct 12 2023(Updated: )
Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP Google Analytics Extension plugin <= 4.0.4 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
MainWP Google Analytics Extension | <=4.0.4 |
Update to 4.0.5 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23651 is an SQL Injection (SQLi) vulnerability in the MainWP Google Analytics Extension plugin.
CVE-2023-23651 has a severity of 8.5, which is considered high.
CVE-2023-23651 affects versions up to and including 4.0.4 of the MainWP Google Analytics Extension plugin.
CVE-2023-23651 allows authenticated users with at least subscriber+ role to perform SQL Injection attacks.
Yes, a fix is available for CVE-2023-23651. It is recommended to update to version 4.0.5 or later of the MainWP Google Analytics Extension plugin.