CVE Vulnerabilities

CVE-2023-1207

Published: May 15, 2023 | Modified: Jan 24, 2025
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

This HTTP Headers WordPress plugin before 1.18.8 has an import functionality which executes arbitrary SQL on the server, leading to an SQL Injection vulnerability.

Affected Software

NameVendorStart VersionEnd Version
Http_headersRiverside*1.18.8 (excluding)

References