peter bassill · operator
$ cve CVE-2023-1730 JSON

CVE-2023-1730

9.8
CRITICAL · CVSS 3.1 · EPSS 40.6% (pctl 99)

Patch early

EPSS 40.6% — above the 10% action threshold.

Description

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS40.59% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploitnone known
Published2023-05-02
Last modified2026-06-17

Affected (1)

VendorProduct
supportcandysupportcandy

References

→ the Explorer  ·  watch your stack  ·  NVD