High severity7.2NVD Advisory· Published Apr 17, 2023· Updated Jun 17, 2026
CVE-2023-0277
CVE-2023-0277
Description
The WC Fields Factory WordPress plugin through 4.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:wc_fields_factory_project:wc_fields_factory:*:*:*:*:*:wordpress:*:*Range: <=4.1.5
- WordPress/WC Fields Factorydescription
- Range: <=4.1.5
Patches
Vulnerability mechanics
References
2- wpscan.com/vulnerability/69ffb2f1-b291-49bf-80a8-08d03ceca53bnvdExploitThird Party Advisory
- bulletin.iese.de/post/wc-fields-factory_1-4-5nvdBroken Link
News mentions
0No linked articles in our index yet.