CVE-2023-28663: SQL Injection
The Formidable PRO2PDF WordPress Plugin, version < 3.11, is affected by an authenticated SQL injection vulnerability in the ‘fieldmap’ parameter in the fpropdfexportfile action.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-28663?
CVE-2023-28663 is an authenticated SQL injection vulnerability in the Formidable PRO2PDF WordPress Plugin version < 3.11.
How does CVE-2023-28663 affect the Formidable PRO2PDF WordPress Plugin?
CVE-2023-28663 affects the Formidable PRO2PDF WordPress Plugin version < 3.11 by allowing authenticated users to inject malicious SQL commands through the 'fieldmap' parameter in the fpropdf_export_file action.
What is the severity of CVE-2023-28663?
CVE-2023-28663 has a severity rating of 8.8 (High).
How can I fix the authenticated SQL injection vulnerability in the Formidable PRO2PDF WordPress Plugin?
To fix the authenticated SQL injection vulnerability in the Formidable PRO2PDF WordPress Plugin, upgrade to version 3.11 or higher.
Where can I find more information about CVE-2023-28663?
You can find more information about CVE-2023-28663 at the following link: https://www.tenable.com/security/research/tra-2023-2