← Back to browse · API

CVE-2023-1730

Severity
CRITICAL
CVSS
9.8
EPSS
0.40586
Risk score
53.41
CISA KEV
No
PoC
No
Published
2023-05-02
Modified
2025-01-30
First seen
2026-08-07
Aliases
EUVD-2023-23953, GHSA-4XMW-QQ98-42Q5
Products
PSM Plugins:SupportCandy 0 <3.1.5
Sources
euvd EUVD-2023-23953

Description

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks

References