CVE Database /
CVE-2023-0234
CVE · High
CVE-2023-0234 — Security Optimizer – The All-In-One Protection Plugin [sg-security] < 1.3.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-0234
|
Security Optimizer – The All-In-One Protection Plugin [sg-security] < 1.3.1 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
8.8
|
< 1.3.1
|
1.3.1 |
2023-01-13 |
—
|
CVE-2023-0234
The SiteGround Security plugin contains a blind SQL injection vulnerability in its filtering and paging parameters that affects versions through 1.3.0, stemming from inadequate escaping of user input and improper query preparation. Administrators with elevated privileges can inject additional SQL commands into existing queries, potentially allowing them to access and exfiltrate confidential data stored in the database. The vulnerability was patched in version 1.3.1.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings