CVE-2023-23660: WordPress MainWP Maintenance Extension Plugin <= 4.1.1 is vulnerable to SQL Injection
Published Jul 18, 2023
·Updated
Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP MainWP Maintenance Extension plugin <= 4.1.1 versions.
Affected Software
1 affected component
MainWP Mainwp Maintenance Extension Wordpress<=4.1.1
Remediation
Information
Update to 4.1.2 or a higher version.
Event History
Jul 18, 2023
CVE Published
via MITRE·12:42 PM
Data Sourced
via MITRE·12:42 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-23660.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP MainWP Maintenance Extension plugin...'.
3
What is the affected software?
The affected software is MainWP MainWP Maintenance Extension plugin version up to and including 4.1.1.
4
What is the severity of CVE-2023-23660?
The severity of CVE-2023-23660 is high with a CVSS score of 8.8.
5
How do I fix CVE-2023-23660?
To fix CVE-2023-23660, update the MainWP MainWP Maintenance Extension plugin to version 4.1.2 or later.