CVE-2023-2111
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2023-2111 is a vulnerability affecting the Fast & Effective Popups & Lead-Generation plugin for WordPress before version 2.1.4. This issue permits administrators in multi-site configurations to potentially leak sensitive information from affected sites' databases. The plugin's report API endpoint concatenates user input directly into SQL queries without proper escaping, creating an vulnerability for SQL injection attacks. This vulnerability could lead to the exposure of confidential database data if exploited. Users of the plugin are advised to upgrade to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.