CVE Database
/

CVE-2023-5082

Back to search

CVE-2023-5082

Published: Nov 6, 2023

Modified: Feb 26, 2025

PUBLISHED

Description

The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when using the Smash Balloon Social Photo Feed plugin alongside it.

VendorProductVersions

Unknown

History Log by click5

affected
0 - < 1.0.13

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now