WP Mail Log < 1.1.3 β Contributor+ SQL Injection in wml_logs endpoint
CVE-2023-5645
What is CVE-2023-5645?
The WP Mail Log plugin for WordPress versions prior to 1.1.3 contains a vulnerability due to inadequate sanitization and escaping of user-supplied data within SQL statements. This weakness allows an attacker with a low-level user role, such as Contributor, to perform SQL injection attacks. By exploiting this vulnerability, malicious users may gain unauthorized access to sensitive data and manipulate the database, highlighting the importance of updating the plugin to the latest version to mitigate risks associated with such security exposures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Mail Log 0 < 1.1.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved