Vulnerability Description
The All In One Redirection WordPress plugin before 2.2.0 does not properly sanitise and escape multiple parameters before using them in an SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vsourz | All In One Redirection | < 2.2.0 |
References
- https://wpscan.com/vulnerability/a9a205a4-eef9-4f30-877a-4c562930650cExploitThird Party Advisory
- https://wpscan.com/vulnerability/a9a205a4-eef9-4f30-877a-4c562930650cExploitThird Party Advisory
FAQ
What is CVE-2023-2493?
CVE-2023-2493 is a vulnerability with a CVSS score of 7.2 (HIGH). The All In One Redirection WordPress plugin before 2.2.0 does not properly sanitise and escape multiple parameters before using them in an SQL statement, leading to a SQL injection exploitable by high...
How severe is CVE-2023-2493?
CVE-2023-2493 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-2493?
Check the references section above for vendor advisories and patch information. Affected products include: Vsourz All In One Redirection.