CVE-2023-38391

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themesgrove Onepage Builder allows SQL Injection.This issue affects Onepage Builder: from n/a through 2.4.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:themesgrove:onepage_builder:*:*:*:*:*:wordpress:*:*

History

29 Apr 2026, 10:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.2
v2 : unknown
v3 : 6.7

28 Apr 2026, 19:21

Type Values Removed Values Added
Summary (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themesgrove Onepage Builder allows SQL Injection.This issue affects Onepage Builder: from n/a through 2.4.1. (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themesgrove Onepage Builder allows SQL Injection.This issue affects Onepage Builder: from n/a through 2.4.1.

21 Nov 2024, 08:13

Type Values Removed Values Added
References () https://patchstack.com/database/vulnerability/tx-onepager/wordpress-onepage-builder-easiest-landing-page-builder-for-wordpress-plugin-2-4-1-sql-injection?_s_id=cve - Third Party Advisory () https://patchstack.com/database/vulnerability/tx-onepager/wordpress-onepage-builder-easiest-landing-page-builder-for-wordpress-plugin-2-4-1-sql-injection?_s_id=cve - Third Party Advisory

09 Nov 2023, 20:07

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
CPE cpe:2.3:a:themesgrove:onepage_builder:*:*:*:*:*:wordpress:*:*
First Time Themesgrove onepage Builder
Themesgrove
References (MISC) https://patchstack.com/database/vulnerability/tx-onepager/wordpress-onepage-builder-easiest-landing-page-builder-for-wordpress-plugin-2-4-1-sql-injection?_s_id=cve - (MISC) https://patchstack.com/database/vulnerability/tx-onepager/wordpress-onepage-builder-easiest-landing-page-builder-for-wordpress-plugin-2-4-1-sql-injection?_s_id=cve - Third Party Advisory

04 Nov 2023, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-04 00:15

Updated : 2026-04-29 10:16


NVD link : CVE-2023-38391

Mitre link : CVE-2023-38391

CVE.ORG link : CVE-2023-38391


JSON object : View

Products Affected

themesgrove

  • onepage_builder
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')