The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL statement, leading to a SQL injection exploitable by users with relatively low privilege on the site, like subscribers.
Metrics
Affected Vendors & Products
References
History
Tue, 10 Jun 2025 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Kaizencoders
Kaizencoders short Url |
|
Weaknesses | CWE-89 | |
CPEs | cpe:2.3:a:kaizencoders:short_url:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Kaizencoders
Kaizencoders short Url |
Mon, 09 Jun 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Fri, 06 Jun 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL statement, leading to a SQL injection exploitable by users with relatively low privilege on the site, like subscribers. | |
Title | Short URL <= 1.6.8 - Subscriber+ SQLi | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-06-06T06:00:05.014Z
Updated: 2025-06-09T19:45:35.897Z
Reserved: 2023-05-26T19:48:42.220Z
Link: CVE-2023-2921

Updated: 2025-06-09T19:26:40.426Z

Status : Analyzed
Published: 2025-06-06T06:15:30.597
Modified: 2025-06-10T19:31:20.783
Link: CVE-2023-2921

No data.