CVE-2023-0329 Information
Jun 02, 2023
cve
Description
The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement leading to a SQL injection exploitable by users with the Administrator role.
Reference
https://wpscan.com/vulnerability/a875836d-77f4-4306-b275-2b60efff1493
Share on: