CVE-2023-0579 Information

Description

The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s which could allow any authenticated users such as subscribers to perform SQL Injection attacks.

Reference

https://wpscan.com/vulnerability/574f7607-96d8-4ef8-b96c-0425ad7e7690

Share on: