WordPress Funnel Builder for WordPress by FunnelKit Plugin <= 2.14.3 is vulnerable to SQL Injection
CVE-2023-50856
7.6HIGH
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 28 December 2023
Summary
An SQL injection vulnerability exists in FunnelKit's Funnel Builder for WordPress, which allows attackers to inject malicious SQL code into database queries. This flaw compromises the security of the application and can lead to unauthorized access to sensitive data. Affected versions include 2.14.3 and earlier. Proper validation and sanitization of user inputs are essential to prevent exploitation of this vulnerability, safeguarding your WooCommerce checkout process and overall site security.
Affected Version(s)
Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels & Maximize Profits <= 2.14.3
References
CVSS V3.1
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Muhammad Daffa (Patchstack Alliance)