WordPress WP Mail Catcher Plugin <= 2.1.3 is vulnerable to SQL Injection
CVE-2023-50844
7.6HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 December 2023
What is CVE-2023-50844?
A vulnerability exists in the WP Mail Catcher plugin by James Ward that allows for improper neutralization of special elements used in SQL commands. This SQL Injection vulnerability can potentially allow an attacker to manipulate database queries, which may lead to unauthorized data access or data alteration. The affected versions range from n/a up to 2.1.3, emphasizing the need for users to update their installations to mitigate risks.
Affected Version(s)
Mail logging – WP Mail Catcher <= 2.1.3