CVE · High

CVE-2023-39309 — Fusion Builder [fusion-builder] < 3.11.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-39309 Fusion Builder [fusion-builder] < 3.11.2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.5 < 3.11.2 3.11.2 2023-08-10

CVE-2023-39309

Fusion Builder before version 3.11.2 contains a SQL injection vulnerability affecting an unspecified parameter. The flaw results from improper escaping of user input and inadequate query parameterization in the plugin's database operations. Authenticated users with subscriber privileges or higher can exploit this to inject malicious SQL commands and retrieve sensitive data from the database.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.