CVE-2023-28662: SQL Injection
The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgvdoajaxvoucherpdfsavefunc action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28662?
CVE-2023-28662 is rated as a high severity vulnerability due to its potential for unauthenticated SQL injection.
How do I fix CVE-2023-28662?
To mitigate CVE-2023-28662, upgrade the Gift Cards WordPress Plugin to version 4.3.2 or later.
Who is affected by CVE-2023-28662?
Any WordPress site using the Gift Cards Plugin version 4.3.1 or lower is vulnerable to CVE-2023-28662.
What kind of attack is associated with CVE-2023-28662?
CVE-2023-28662 is associated with an unauthenticated SQL injection attack, which allows attackers to execute arbitrary SQL commands.
What should I do if I'm unable to update for CVE-2023-28662?
If updating is not possible for CVE-2023-28662, consider disabling the plugin temporarily and monitoring for any suspicious activity.