High severity7.2NVD Advisory· Published Jan 16, 2024· Updated Jun 17, 2026
CVE-2023-2655
CVE-2023-2655
Description
The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=1.13.23+ 1 more
- (no CPE)range: <=1.13.23
- (no CPE)range: <=1.13.23
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/b3f2d38f-8eeb-45e9-bb58-2957e416e1cd/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.