← Back to CVE List

CVE-2023-0098

Published: 2023-02-13T15:15Z
Last Modified: 2025-03-21T20:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt