CVE-2023-26325: SQL Injection
The 'rxexportreview' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterValue' and 'selectedColumns' parameters.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-26325?
CVE-2023-26325 is an authenticated SQL injection vulnerability in the 'filterValue' and 'selectedColumns' parameters of the rx_export_review action in the ReviewX WordPress Plugin.
What is the severity of CVE-2023-26325?
CVE-2023-26325 has a severity rating of 8.8 (high).
Which version of ReviewX WordPress Plugin is affected by CVE-2023-26325?
ReviewX WordPress Plugin version up to 1.6.4 is affected by CVE-2023-26325.
How does CVE-2023-26325 impact WordPress websites?
CVE-2023-26325 allows attackers to perform authenticated SQL injection, potentially leading to unauthorized access and manipulation of the WordPress database.
How can I mitigate the CVE-2023-26325 vulnerability in ReviewX WordPress Plugin?
To mitigate CVE-2023-26325, update ReviewX WordPress Plugin to a version beyond 1.6.4 as soon as a fix is available.