Security Advisory

CVE-2023-2719

8.8
HIGH

Vulnerability Description

The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in the REST API before using it in an SQL statement, leading to an SQL Injection exploitable by users with a role as low as Subscriber.
Published Date June 19, 2023
Official Source NIST NVD Advisory