PoC Index

CVE-2023-1730

CRITICAL 9.8EPSS 40.6%

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
40.59% chance of exploitation in the next 30 days, 99th percentile
Nuclei
critical · CWE-89
Published
2023-05-02
Updated
2025-01-30

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related