Vulnerabilities (CVE)

Filtered by vendor Wp Brutal Ai Project Subscribe
Filtered by product Wp Brutal Ai
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-2601 1 Wp Brutal Ai Project 1 Wp Brutal Ai 2023-08-02 N/A 9.8 CRITICAL
The wpbrutalai WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin via CSRF.