CVE-2023-2719

SupportCandy < 3.1.7 - Subscriber+ SQLi

The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in the REST API before using it in an SQL statement, leading to an SQL Injection exploitable by users with a role as low as Subscriber.


We have discovered 370 live websites that are affected by CVE-2023-2719.

Run a Free Instant Scan




Affected Software

Product  Supportcandy
Category Wordpress Plugins
Vulnerable Domains370 live websites (18% of Supportcandy install base)
Vulnerable Versions
  • from 0 through 3.1.7
Vulnerable Versions Count26 versions ( 50% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Jun 19, 2023
  • Updated - Dec 12, 2024

Credits

  • dc11 (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2023-2719
United States86 websites



Italy41 websites
Germany29 websites
Iran24 websites
Russia20 websites
GB18 websites
Brazil16 websites
France16 websites
Spain11 websites
Australia9 websites

Website Distribution by TLD

Number of websites using CVE-2023-2719
.com135 websites
.it31 websites
.ru18 websites
.com.br17 websites
.net11 websites
.org10 websites
.de8 websites
.pl6 websites
.com.au5 websites
.eu5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-2719

Top websites that are affected by CVE-2023-2719. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.app Bulgaria**,***
****************.com GB**,***
********.pt United States**,***
*****.sv El Salvador***,***
*****************.com United States***,***
***********.com United States***,***
*********.com United States***,***
*********.de Germany***,***
************.***.au Australia***,***
************.com United States***,***
See full domain list

FAQ

CVE-2023-2719 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Supportcandy
A total of 370 websites have been identified as vulnerable to CVE-2023-2719, based on global website indexing conducted by WebTechSurvey.
The Supportcandy is affected by the CVE-2023-2719 vulnerability.
Supportcandy versions up to 3.1.7 are vulnerable to CVE-2023-2719.
CVE-2023-2719 is resolved in version 3.1.7 of Supportcandy.