Vulnerability Description
The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elementor | Website Builder | < 3.12.2 |
References
- http://packetstormsecurity.com/files/175639/Elementor-Website-Builder-SQL-Inject
- https://wpscan.com/vulnerability/a875836d-77f4-4306-b275-2b60efff1493ExploitThird Party Advisory
- http://packetstormsecurity.com/files/175639/Elementor-Website-Builder-SQL-Inject
- https://wpscan.com/vulnerability/a875836d-77f4-4306-b275-2b60efff1493ExploitThird Party Advisory
FAQ
What is CVE-2023-0329?
CVE-2023-0329 is a vulnerability with a CVSS score of 7.2 (HIGH). The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL in...
How severe is CVE-2023-0329?
CVE-2023-0329 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-0329?
Check the references section above for vendor advisories and patch information. Affected products include: Elementor Website Builder.