Vulnerability Description
The Fast & Effective Popups & Lead-Generation for WordPress plugin before 2.1.4 concatenates user input into an SQL query without escaping it first in the plugin's report API endpoint, which could allow administrators in multi-site configuration to leak sensitive information from the site's database.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Groundhogg | Hollerbox | < 2.1.4 |
References
- https://wpscan.com/vulnerability/7a0bdd47-c339-489d-9443-f173a83447f2Exploit
- https://wpscan.com/vulnerability/7a0bdd47-c339-489d-9443-f173a83447f2Exploit
FAQ
What is CVE-2023-2111?
CVE-2023-2111 is a vulnerability with a CVSS score of 4.9 (MEDIUM). The Fast & Effective Popups & Lead-Generation for WordPress plugin before 2.1.4 concatenates user input into an SQL query without escaping it first in the plugin's report API endpoint, which could all...
How severe is CVE-2023-2111?
CVE-2023-2111 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-2111?
Check the references section above for vendor advisories and patch information. Affected products include: Groundhogg Hollerbox.