Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12356 | The WC Fields Factory WordPress plugin through 4.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin |
Thu, 06 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-02-06T15:30:15.424Z
Reserved: 2023-01-13T08:59:18.116Z
Link: CVE-2023-0277
Updated: 2024-08-02T05:02:44.141Z
Status : Modified
Published: 2023-04-17T13:15:37.723
Modified: 2025-02-06T16:15:32.083
Link: CVE-2023-0277
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD