SQL Injection Vulnerability in Wp Photo Text Slider 50 Plugin for WordPress
CVE-2023-5439
8.8HIGH
What is CVE-2023-5439?
The Wp Photo Text Slider 50 plugin for WordPress is susceptible to SQL Injection due to inadequate parameter escaping. This vulnerability allows authenticated users with subscriber-level permissions or higher to manipulate existing SQL queries through the plugin's shortcode. Such exploits could lead to unauthorized access to sensitive database information, posing significant risks to user data integrity and privacy.
Affected Version(s)
Wp photo text slider 50 * <= 8.0