CVE-2023-6373

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
16/01/2024
Last modified:
11/06/2025

Description

The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting the query, leading to a SQLI exploitable by editors and above. Note: Due to the lack of CSRF check, the issue could also be exploited via a CSRF against a logged editor (or above)

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:artplacer:artplacer_widget:*:*:*:*:*:wordpress:*:* 2.20.6 (including)