CVE · High

CVE-2023-50848 — 404 Solution [404-solution] < 2.35.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-50848 404 Solution [404-solution] < 2.35.0 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.6 < 2.35.0 2.35.0 2023-12-21

CVE-2023-50848

The 404 Solution plugin for WordPress contains a SQL injection vulnerability affecting all versions before 2.35.0. An unspecified parameter fails to properly escape user input and the associated SQL query lacks adequate preparation, allowing administrators and higher-privileged users to inject arbitrary SQL commands. Attackers with these elevated permissions could exploit this flaw to extract sensitive data from the WordPress database by appending malicious SQL queries to existing ones.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.