CVE · High

CVE-2023-6967 — Pods - Custom Content Types and Fields [pods] < 3.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6967 Pods - Custom Content Types and Fields [pods] < 3.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 3.1 3.1 2024-03-28

CVE-2023-6967

The Pods – Custom Content Types and Fields plugin contains a SQL injection vulnerability in its shortcode functionality affecting versions up to 3.0.10, excluding patched releases 2.7.31.2, 2.8.23.2, and 2.9.19.2. Inadequate escaping of user-supplied parameters combined with insufficient query preparation allows authenticated users with contributor-level permissions or greater to inject malicious SQL code into existing database queries. This vulnerability enables attackers to execute unauthorized queries that could expose sensitive database information.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.