cleantalk
Vulnerabilities and Security Researches

EazyDocs – Most Powerful Knowledge base, wiki, Documentation Builder Plugin (easy docs, knowledgebase), CVE-2023-6035

CVE, Research URL

CVE-2023-6035

Published on
Dec 12, 2023
Research Description
The EazyDocs WordPress plugin before 2.3.4 does not properly sanitize and escape "data" parameter before using it in an SQL statement via an AJAX action, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.
Affected versions
Min -, max 2.3.4.
Status
vulnerable