VYPR
Unrated severityNVD Advisory· Published Jun 6, 2025· Updated Jun 9, 2025

Short URL <= 1.6.8 - Subscriber+ SQLi

CVE-2023-2921

Description

The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL statement, leading to a SQL injection exploitable by users with relatively low privilege on the site, like subscribers.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.