CVE-2024-3060
26.04.2024, 05:15
The ENL Newsletter WordPress plugin through 1.0.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin+ to perform SQL injection attacks
Vendor | Product | Version |
---|---|---|
enl_newsletter_plugin_project | enl-newsletter | 𝑥 ≤ 1.0.1 |
𝑥
= Vulnerable software versions