CVE-2023-2719: SupportCandy < 3.1.7 - Subscriber+ SQLi
The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the id parameter for an Agent in the REST API before using it in an SQL statement, leading to an SQL Injection exploitable by users with a role as low as Subscriber.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2719?
CVE-2023-2719 is a SQL Injection vulnerability in the SupportCandy WordPress plugin before version 3.1.7.
How severe is CVE-2023-2719?
CVE-2023-2719 has a severity score of 8.8 (high).
What is affected by CVE-2023-2719?
The SupportCandy WordPress plugin versions up to and excluding 3.1.7 are affected by CVE-2023-2719.
How can I fix CVE-2023-2719?
To fix CVE-2023-2719, you should update the SupportCandy WordPress plugin to version 3.1.7 or later.
Where can I find more information about CVE-2023-2719?
You can find more information about CVE-2023-2719 at the following reference link: https://wpscan.com/vulnerability/d9f6f4e7-a237-49c0-aba0-2934ab019e35