← Back to browse · API

CVE-2023-2114

Severity
HIGH
CVSS
7.2
EPSS
0.44629
Risk score
44.42
CISA KEV
No
PoC
No
Published
2023-05-08
Modified
2025-02-04
First seen
2026-08-07
Aliases
EUVD-2023-33635, GHSA-8GRP-3H33-9G72
Products
Basix:NEX-Forms 0 <8.4
Sources
euvd EUVD-2023-33635

Description

The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query.

References