← Back to CVE List

CVE-2023-6035

Published: 2023-12-11T20:15Z
Last Modified: 2024-11-21T08:43Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The EazyDocs WordPress plugin before 2.3.4 does not properly sanitize and escape "data" parameter before using it in an SQL statement via an AJAX action, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt