CVE-2023-41685: WordPress Woocommerce Support System plugin <= 1.2.1 - SQL Injection vulnerability
Published Nov 6, 2023
·Updated
A vulnerability in ilGhera Woocommerce Support System wc-support-system.This issue affects Woocommerce Support System: from n/a through <= 1.2.1.
Affected Software
1 affected component
ilGhera Woocommerce Support System Wordpress<=1.2.1
Event History
Nov 6, 2023
CVE Published
via MITRE·08:17 AM
Data Sourced
via MITRE·08:17 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-41685?
The severity of CVE-2023-41685 is critical, with a CVSS score of 9.8.
2
How does CVE-2023-41685 affect the Woocommerce Support System?
CVE-2023-41685 allows SQL Injection in the Woocommerce Support System plugin version 1.2.1 and earlier.
3
What is SQL Injection?
SQL Injection is a vulnerability that allows an attacker to manipulate or execute unauthorized SQL commands in a database.
4
How can I fix the CVE-2023-41685 vulnerability?
To fix CVE-2023-41685, update the Woocommerce Support System plugin to a version higher than 1.2.1.
5
Where can I find more information about CVE-2023-41685?
More information about CVE-2023-41685 can be found at the following reference: [LINK]