What the vulnerability does
01Description
Unauthenticated SQL Injection (SQLi) vulnerability discovered in [GWA] AutoResponder WordPress plugin (versions <= 2.3), vulnerable at (&listid). No patched version available, plugin closed.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
What the vulnerability does
Unauthenticated SQL Injection (SQLi) vulnerability discovered in [GWA] AutoResponder WordPress plugin (versions <= 2.3), vulnerable at (&listid). No patched version available, plugin closed.
Explanation of Vulnerability in Simple Terms
The [GWA] AutoResponder WordPress plugin version 2.3 and earlier contains a SQL injection vulnerability in its database queries. An unauthenticated attacker can send a specially crafted request to extract, modify, or delete data from the site's database. No user interaction or special privileges are required to exploit this flaw.
What an attacker can do
Read, modify, or delete data from the site's database without authentication.
Potential impact on your site
Attackers can steal sensitive data, modify site content, or disrupt site functionality without logging in.
Conditions required to exploit
Network access to the WordPress site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities