WordPress Funnel Builder for WordPress by FunnelKit Plugin <= 2.14.3 is vulnerable to SQL Injection
CVE-2023-50856
7.6HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 28 December 2023
What is CVE-2023-50856?
An SQL injection vulnerability exists in FunnelKit's Funnel Builder for WordPress, which allows attackers to inject malicious SQL code into database queries. This flaw compromises the security of the application and can lead to unauthorized access to sensitive data. Affected versions include 2.14.3 and earlier. Proper validation and sanitization of user inputs are essential to prevent exploitation of this vulnerability, safeguarding your WooCommerce checkout process and overall site security.
Affected Version(s)
Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels & Maximize Profits <= 2.14.3