CVE-2023-0630
HIGH NUCLEIWp-slimstat Slimstat Analytics < 4.9.3.3 - SQL Injection
Title source: ruleDescription
The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that concatenates attributes directly into an SQL query.
Exploits (1)
Nuclei Templates (1)
Slimstat Analytics < 4.9.3.3 Subscriber - SQL Injection
HIGHVERIFIEDby DhiyaneshDK
Scores
CVSS v3
8.8
EPSS
0.9024
EPSS Percentile
99.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
wp-slimstat/slimstat_analytics
< 4.9.3.3
Published
Mar 20, 2023
Tracked Since
Feb 18, 2026