SQL Injection Vulnerability in Vertical Marquee Plugin for WordPress
CVE-2023-5436
8.8HIGH
Summary
The Vertical Marquee plugin for WordPress suffers from a SQL injection vulnerability due to inadequate escaping of user-supplied parameters in its shortcode. This issue allows authenticated users with subscriber-level permissions and above to manipulate existing SQL queries, potentially extracting sensitive data from the database. It is crucial for site administrators to update to the latest version and apply best practices to secure their WordPress installations from such vulnerabilities.
Affected Version(s)
Vertical marquee plugin * <= 7.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lana Codes