CVE-2023-2921

The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL statement, leading to a SQL injection exploitable by users with relatively low privilege on the site, like subscribers.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kaizencoders:short_url:*:*:*:*:*:wordpress:*:*

History

10 Jun 2025, 19:31

Type Values Removed Values Added
First Time Kaizencoders short Url
Kaizencoders
CPE cpe:2.3:a:kaizencoders:short_url:*:*:*:*:*:wordpress:*:*
CWE CWE-89
References () https://wpscan.com/vulnerability/0f85db4f-8493-4941-8f3c-e5258c581bdc/ - () https://wpscan.com/vulnerability/0f85db4f-8493-4941-8f3c-e5258c581bdc/ - Exploit, Third Party Advisory

09 Jun 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
References () https://wpscan.com/vulnerability/0f85db4f-8493-4941-8f3c-e5258c581bdc/ - () https://wpscan.com/vulnerability/0f85db4f-8493-4941-8f3c-e5258c581bdc/ -

06 Jun 2025, 14:07

Type Values Removed Values Added
Summary
  • (es) El complemento Short URL de WordPress hasta la versión 1.6.8 no depura ni escapa adecuadamente un parámetro antes de usarlo en una declaración SQL, lo que genera una inyección SQL explotable por usuarios con privilegios relativamente bajos en el sitio, como los suscriptores.

06 Jun 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-06 06:15

Updated : 2025-06-10 19:31


NVD link : CVE-2023-2921

Mitre link : CVE-2023-2921

CVE.ORG link : CVE-2023-2921


JSON object : View

Products Affected

kaizencoders

  • short_url
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')