CVE Database
/

CVE-2023-2493

Back to search

CVE-2023-2493

Published: Jul 10, 2023

Modified: Nov 12, 2024

PUBLISHED

Description

The All In One Redirection WordPress plugin before 2.2.0 does not properly sanitise and escape multiple parameters before using them in an SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

VendorProductVersions

Unknown

All In One Redirection

affected
0 - < 2.2.0

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now