[CVE-2023-0895] WP Coder, Version 2.5.3 Advisory
bishopfox.com | vulnerability | CVE-2023-0895 | #sql-injection | #wordpress | #vulnerability | #security-advisory | #wp-coder | #cve-2023-0895
Summary
Advisory on CVE-2023-0895: the WP Coder WordPress plugin (≤2.5.3) has a time-based SQL injection via the 'id' parameter, letting authenticated admins read sensitive database contents; fixed in 2.5.4.
- Published
- Collected
Skip to content