CVE-2023-2921

The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL statement, leading to a SQL injection exploitable by users with relatively low privilege on the site, like subscribers.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kaizencoders:short_url:*:*:*:*:*:wordpress:*:*

History

10 Jun 2025, 19:31

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/0f85db4f-8493-4941-8f3c-e5258c581bdc/ - () https://wpscan.com/vulnerability/0f85db4f-8493-4941-8f3c-e5258c581bdc/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:kaizencoders:short_url:*:*:*:*:*:wordpress:*:*
First Time Kaizencoders
Kaizencoders short Url
CWE CWE-89

09 Jun 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
References () https://wpscan.com/vulnerability/0f85db4f-8493-4941-8f3c-e5258c581bdc/ - () https://wpscan.com/vulnerability/0f85db4f-8493-4941-8f3c-e5258c581bdc/ -

06 Jun 2025, 14:07

Type Values Removed Values Added
Summary
  • (es) El complemento Short URL de WordPress hasta la versión 1.6.8 no depura ni escapa adecuadamente un parámetro antes de usarlo en una declaración SQL, lo que genera una inyección SQL explotable por usuarios con privilegios relativamente bajos en el sitio, como los suscriptores.

06 Jun 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-06 06:15

Updated : 2025-06-10 19:31


NVD link : CVE-2023-2921

Mitre link : CVE-2023-2921

CVE.ORG link : CVE-2023-2921


JSON object : View

Products Affected

kaizencoders

  • short_url
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')