WordPress Transbank Webpay REST Plugin <= 1.6.6 is vulnerable to SQL Injection
CVE-2023-27610
5.5MEDIUM
What is CVE-2023-27610?
An authentication bypass leading to an SQL Injection vulnerability has been identified in the Transbank Webpay REST plugin versions 1.6.6 and earlier. This flaw allows an authenticated user with administrative privileges to execute arbitrary SQL queries on the database, potentially exposing sensitive data and compromising site security. The issue arises from improper validation and sanitization of user input, highlighting the necessity for timely updates and security patches to mitigate risks.
Affected Version(s)
Transbank Webpay REST <= 1.6.6