CVE-2023-6620: Post SMTP < 2.8.7 - Admin+ SQL Injection
Published Jan 15, 2024
·Updated
The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using them in SQL statements, leading to a SQL injection exploitable by high privilege users such as admin.
Affected Software
1 affected component
Wpexperts Post Smtp Wordpress<2.8.7
Event History
Jan 15, 2024
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-6620?
CVE-2023-6620 has a high severity rating due to the risk of SQL injection by high privilege users.
2
How do I fix CVE-2023-6620?
To fix CVE-2023-6620, update the Post SMTP Mailer plugin to version 2.8.7 or later.
3
Who is affected by CVE-2023-6620?
CVE-2023-6620 affects users of the Post SMTP Mailer WordPress plugin prior to version 2.8.7.
4
Can CVE-2023-6620 be exploited by anyone?
CVE-2023-6620 can be exploited primarily by users with high privileges, such as administrators.
5
What does CVE-2023-6620 allow an attacker to do?
CVE-2023-6620 allows an attacker to execute unauthorized SQL commands within the database.