CVE-2023-26525: WordPress Dokan Plugin <= 3.7.12 is vulnerable to SQL Injection
Published Dec 20, 2023
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: from n/a through 3.7.12.
Affected Software
1 affected component
Dokan Dokan WordPress<3.7.13
Remediation
Information
Update to 3.7.13 or a higher version.
Event History
Dec 20, 2023
CVE Published
via MITRE·05:27 PM
Data Sourced
via MITRE·05:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-26525?
CVE-2023-26525 has a medium severity rating due to its potential for SQL injection attacks.
2
How do I fix CVE-2023-26525?
To fix CVE-2023-26525, update the Dokan plugin to version 3.7.13 or later.
3
What software is affected by CVE-2023-26525?
CVE-2023-26525 affects the weDevs Dokan plugin versions prior to 3.7.13.
4
What type of vulnerability is CVE-2023-26525?
CVE-2023-26525 is classified as an SQL injection vulnerability.
5
Can CVE-2023-26525 be exploited remotely?
Yes, CVE-2023-26525 can be exploited remotely by attackers with access to the affected software.