WordPress Sayfa Sayaç Plugin <= 2.6 is vulnerable to SQL Injection
CVE-2023-49776
9.3CRITICAL
What is CVE-2023-49776?
The Sayfa Sayac plugin developed by Hakan Demiray is susceptible to an SQL Injection vulnerability, particularly in versions from n/a through 2.6. This flaw arises from improper handling of special elements within SQL commands, potentially allowing unauthorized users to execute arbitrary SQL queries. This could lead to unauthorized access to sensitive data within the database, posing a significant risk to WordPress sites utilizing this plugin. It is imperative for users to update to the latest version or apply necessary security measures to safeguard their websites.
Affected Version(s)
Sayfa Sayac <= 2.6