CVE-2023-23489 is an unauthenticated SQL injection vulnerability impacting Easy Digital Downloads WordPress Plugin versions 3.1.0.2 and 3.1.0.3, specifically within the 's' parameter of its 'edd_download_search' action. This critical vulnerability carries a CVSS score of 9.8, indicating a severe risk with network-based exploitation, low attack complexity, and high potential for compromise of confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog, public Proof-of-Concept exploits have been released, and Nuclei templates exist for detection, suggesting a high likelihood of exploitation. The vulnerability has garnered significant community discussion and media coverage, further emphasizing its importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.0.4CPE matchmatch criteria | cpe:2.3:a:sandhillsdev:easy_digital_downloads:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
SQL Injection in Multiple WordPress Plugins
Jan 12, 2023SQL Injection in Multiple WordPress Plugins
Jan 12, 2023SQL Injection in Multiple WordPress Plugins
Jan 12, 2023SQL Injection in Multiple WordPress Plugins
Jan 12, 2023