WordPress WebinarIgnition Plugin <= 3.05.0 is vulnerable to SQL Injection
CVE-2023-51423

9.3CRITICAL

Summary

An SQL Injection vulnerability exists within the Saleswonder Webinar Plugin, utilized for creating live and automated webinars. This issue arises from improper handling of special elements within SQL commands, allowing unauthorized users to manipulate database queries. If exploited, this vulnerability could lead to unauthorized access or data manipulation, endangering user data and overall system integrity. Users are advised to update their plugins to mitigate this risk.

Affected Version(s)

Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition <= 3.05.0

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.