CVE-2023-3211

CVE-2023-3211: WordPress Database Administrator <= 1.0.3 - Unauthenticated SQL Injection

Vendor Unknown
Product WordPress Database Administrator
Published January 16, 2024
Last update June 11, 2025

CVSS base score

What the vulnerability does

01Description

The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

Key dates

02Disclosure timeline

January 16, 2024 CVE published
June 11, 2025 Record updated