Vulnerability Description
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for attackers, with an existing account on a vulnerable WordPress instance, to extract potentially sensitive information from the LDAP directory.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Miniorange | Active Directory Integration \/ Ldap Integration | < 4.1.6 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&oldPatch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/cd7553e8-e43d-4740-b2eThird Party Advisory
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&oldPatch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/cd7553e8-e43d-4740-b2eThird Party Advisory
FAQ
What is CVE-2023-3447?
CVE-2023-3447 is a vulnerability with a CVSS score of 7.6 (HIGH). The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied u...
How severe is CVE-2023-3447?
CVE-2023-3447 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-3447?
Check the references section above for vendor advisories and patch information. Affected products include: Miniorange Active Directory Integration \/ Ldap Integration.