CVE-2023-5645: WP Mail Log < 1.1.3 – Contributor+ SQL Injection in wml_logs endpoint
Published Dec 26, 2023
·Updated
The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor.
Affected Software
1 affected component
WPVibes Wp Mail Log Wordpress<1.1.3
Event History
Dec 26, 2023
CVE Published
via MITRE·06:33 PM
Data Sourced
via MITRE·06:33 PM
DescriptionWeakness
May 24, 57290
Event
via FIRST·01:24 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-5645?
CVE-2023-5645 is classified as a high severity vulnerability due to its potential for SQL injection exploitation.
2
How do I fix CVE-2023-5645?
To fix CVE-2023-5645, update the WP Mail Log plugin to version 1.1.3 or later.
3
Who can exploit CVE-2023-5645?
CVE-2023-5645 can be exploited by users with a role as low as Contributor.
4
What kind of vulnerability is CVE-2023-5645?
CVE-2023-5645 is a SQL injection vulnerability related to improper sanitization and escaping of parameters.
5
What software is affected by CVE-2023-5645?
CVE-2023-5645 affects the WP Mail Log WordPress plugin versions prior to 1.1.3.