Vulnerability Description
The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the agents[] parameter in the set_add_agent_leaves AJAX function before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Supportcandy | Supportcandy | < 3.1.7 |
References
- https://wpscan.com/vulnerability/bdb75c8c-87e2-4358-ad3b-f4236e9a43c0ExploitThird Party Advisory
- https://wpscan.com/vulnerability/bdb75c8c-87e2-4358-ad3b-f4236e9a43c0ExploitThird Party Advisory
FAQ
What is CVE-2023-2805?
CVE-2023-2805 is a vulnerability with a CVSS score of 7.2 (HIGH). The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the agents[] parameter in the set_add_agent_leaves AJAX function before using it in a SQL statement, leading to a S...
How severe is CVE-2023-2805?
CVE-2023-2805 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-2805?
Check the references section above for vendor advisories and patch information. Affected products include: Supportcandy Supportcandy.