High severity7.5NVD Advisory· Published Dec 26, 2023· Updated Jun 17, 2026
CVE-2023-5203
CVE-2023-5203
Description
The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an error/union based technique.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- WordPress/WP Sessions Time Monitoring Full Automatic WordPress plugindescription
- Range: <1.0.9
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.