CVE Vulnerabilities

CVE-2023-1207

Published: May 15, 2023 | Modified: Jan 24, 2025
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

This HTTP Headers WordPress plugin before 1.18.8 has an import functionality which executes arbitrary SQL on the server, leading to an SQL Injection vulnerability.

Affected Software

Name Vendor Start Version End Version
Http_headers Riverside * 1.18.8 (excluding)

References