cve/2023/CVE-2023-2761.md
2024-05-28 08:49:17 +00:00

805 B

CVE-2023-2761

Description

The User Activity Log WordPress plugin before 1.6.3 does not properly sanitise and escape the txtsearch parameter before using it in a SQL statement in some admin pages, leading to a SQL injection exploitable by high privilege users such as admin.

POC

Reference

Github