SupportCandy < 3.1.7 - Subscriber+ SQLi
CVE-2023-2719
8.8HIGH
What is CVE-2023-2719?
The SupportCandy plugin for WordPress, prior to version 3.1.7, is susceptible to an SQL Injection vulnerability due to improper sanitization and escaping of the 'id' parameter used in the REST API for an Agent. This weakness allows users with minimal privileges, such as subscribers, to execute malicious SQL queries, potentially compromising site integrity and data security.
Affected Version(s)
SupportCandy 0 < 3.1.7