CVE-2023-0277
17.04.2023, 13:15
The WC Fields Factory WordPress plugin through 4.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as adminEnginsight
Vendor | Product | Version |
---|---|---|
wc_fields_factory_project | wc_fields_factory | 𝑥 ≤ 4.1.5 |
𝑥
= Vulnerable software versions