CVE-2023-1730

SupportCandy < 3.1.5 - Unauthenticated SQLi

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks


We have discovered 368 live websites that are affected by CVE-2023-1730.

Run a Free Instant Scan




Affected Software

Product  Supportcandy
Category Wordpress Plugins
Vulnerable Domains368 live websites (18% of Supportcandy install base)
Vulnerable Versions
  • from 0 through 3.1.5
Vulnerable Versions Count25 versions ( 48% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - May 2, 2023
  • Updated - Jan 30, 2025

Credits

  • dc11 (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2023-1730
United States85 websites



Italy41 websites
Germany29 websites
Iran24 websites
Russia20 websites
GB18 websites
Brazil16 websites
France16 websites
Spain11 websites
Australia9 websites

Website Distribution by TLD

Number of websites using CVE-2023-1730
.com134 websites
.it31 websites
.ru18 websites
.com.br17 websites
.net11 websites
.org10 websites
.de8 websites
.pl6 websites
.com.au5 websites
.eu5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-1730

Top websites that are affected by CVE-2023-1730. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.app Bulgaria**,***
****************.com GB**,***
********.pt United States**,***
*****.sv El Salvador***,***
*****************.com United States***,***
***********.com United States***,***
*********.com United States***,***
*********.de Germany***,***
************.***.au Australia***,***
************.com United States***,***
See full domain list

FAQ

CVE-2023-1730 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Supportcandy
A total of 368 websites have been identified as vulnerable to CVE-2023-1730, based on global website indexing conducted by WebTechSurvey.
The Supportcandy is affected by the CVE-2023-1730 vulnerability.
Supportcandy versions up to 3.1.5 are vulnerable to CVE-2023-1730.
CVE-2023-1730 is resolved in version 3.1.5 of Supportcandy.