Unrated severityNVD Advisory· Published Apr 24, 2023· Updated Feb 4, 2025
Steveas WP Live Chat Shoutbox <= 1.4.2 - Unauthenticated SQLi
CVE-2023-1020
Description
The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
Affected products
1- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/4e5aa9a3-65a0-47d6-bc26-a2fb6cb073ffmitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.