CVE-2023-2493: Vsourz All In One Redirection
High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.
The All In One Redirection WordPress plugin before 2.2.0 does not properly sanitise and escape multiple parameters before using them in an SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
Affected products
- Vsourz All In One Redirection: before 2.2.0 (fixed in 2.2.0)
Published 2023-07-10. Last modified 2026-06-17.