Showing 1 vulnerability on this page for bestbooks

Signals CISA KEV Ransomware Nuclei
presspage vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Bestbooks <= 2.6.3 - Unauthenticated SQLi

The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CWE-89Jun 13, 20221 related artifact
CVSS9.8v3.1EPSS9.24%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX