ZeroHour

CVE-2023-0224

PoC
CVSS 3.1
9.8 critical
EPSS
4%p89
Published
()
Modified
Description

The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers perform SQL Injection attacks

Vendors
givewp
Products
givewp
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.