CVE-2023-5434: Superb slideshow gallery <= 13.1 - Authenticated (Subscriber+) SQL Injection via Shortcode
The Superb slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 13.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-5434.
What is the affected software?
The affected software is the Superb slideshow gallery plugin for WordPress.
What is the severity of CVE-2023-5434?
The severity of CVE-2023-5434 is high, with a severity value of 8.8.
How does CVE-2023-5434 work?
CVE-2023-5434 is a SQL Injection vulnerability that occurs due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
How can I fix CVE-2023-5434?
To fix CVE-2023-5434, it is recommended to update to a version of the Superb slideshow gallery plugin for WordPress that is beyond version 13.2, where the vulnerability is patched.