SQL Injection Vulnerability in Vertical Marquee Plugin for WordPress
CVE-2023-5436
8.8HIGH
What is CVE-2023-5436?
The Vertical Marquee plugin for WordPress suffers from a SQL injection vulnerability due to inadequate escaping of user-supplied parameters in its shortcode. This issue allows authenticated users with subscriber-level permissions and above to manipulate existing SQL queries, potentially extracting sensitive data from the database. It is crucial for site administrators to update to the latest version and apply best practices to secure their WordPress installations from such vulnerabilities.
Affected Version(s)
Vertical marquee plugin * <= 7.1