Record summary

CVE-2023-1730 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 30, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

SupportCandy

Default status: unaffected

CVE ListBefore 3.1.5affected

Nuclei templates

1
ProjectDiscoveryCRITICALSupportCandy < 3.1.5 - Unauthenticated SQL InjectionCVSS 9.8

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.

Remediation

Fixed in version 3.1.5

WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicve2023cvesqliwpscanwordpresssupportcandyunauthvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:supportcandy:supportcandy:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2