WP Mail Log < 1.1.3 – Contributor+ SQL Injection in wml_logs endpoint
CVE-2023-5645
8.8HIGH
What is CVE-2023-5645?
The WP Mail Log plugin for WordPress versions prior to 1.1.3 contains a vulnerability due to inadequate sanitization and escaping of user-supplied data within SQL statements. This weakness allows an attacker with a low-level user role, such as Contributor, to perform SQL injection attacks. By exploiting this vulnerability, malicious users may gain unauthorized access to sensitive data and manipulate the database, highlighting the importance of updating the plugin to the latest version to mitigate risks associated with such security exposures.
Affected Version(s)
WP Mail Log 0 < 1.1.3