WordPress MainWP Maintenance Extension Plugin <= 4.1.1 is vulnerable to SQL Injection
CVE-2023-23660

8.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 July 2023

What is CVE-2023-23660?

The MainWP Maintenance Extension plugin, used within WordPress, is susceptible to an authenticated SQL injection vulnerability impacting versions up to 4.1.1. This flaw allows attackers with subscriber-level access or higher to exploit the plugin, potentially leading to unauthorized database access and manipulation. Proper measures should be taken to secure WordPress installations by updating the plugin to mitigate risks associated with this vulnerability.

Affected Version(s)

MainWP Maintenance Extension <= 4.1.1

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dave Jong (Patchstack)
.