CVE-2023-32590
CRITICAL NUCLEISubscribe to Category < 2.7.4 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-32590. PoCs published by RandomRobbieBF. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a proof-of-concept for CVE-2023-32590, an unauthenticated SQL injection vulnerability in the Subscribe to Category WordPress plugin (versions up to 2.7.4). The PoC includes a SQLMap scan demonstrating time-based blind SQL injection via the 'sender' parameter in a JSON payload.
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category.This issue affects Subscribe to Category: from n/a through 2.7.4.
Exploits (1)
This repository contains a proof-of-concept for CVE-2023-32590, an unauthenticated SQL injection vulnerability in the Subscribe to Category WordPress plugin (versions up to 2.7.4). The PoC includes a SQLMap scan demonstrating time-based blind SQL injection via the 'sender' parameter in a JSON payload.
Nuclei Templates (1)
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L