CVE-2023-45055: WordPress MStore API Plugin <= 4.0.6 is vulnerable to SQL Injection
Published Nov 6, 2023
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InspireUI MStore API allows SQL Injection.This issue affects MStore API: from n/a through 4.0.6.
Affected Software
1 affected component
InspireUI Mstore Api Wordpress<4.0.7
Remediation
Information
Update to 4.0.7 or a higher version.
Event History
Nov 6, 2023
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-45055?
CVE-2023-45055 is a SQL Injection vulnerability in the WordPress MStore API Plugin version <= 4.0.6.
2
How severe is CVE-2023-45055?
CVE-2023-45055 has a severity rating of 9.8 (critical).
3
What software is affected by CVE-2023-45055?
The InspireUI MStore API version from n/a through 4.0.6 is affected by CVE-2023-45055.
4
How can I fix CVE-2023-45055?
To fix CVE-2023-45055, update the WordPress MStore API Plugin to version 4.0.7 or newer.
5
What is the Common Weakness Enumeration (CWE) category for CVE-2023-45055?
The CWE category for CVE-2023-45055 is CWE-89 (SQL Injection).