Vulnerabilities > WP Custom Cursors Project > WP Custom Cursors > High

DATE CVE VULNERABILITY TITLE RISK
2023-06-19 CVE-2023-2221 Unspecified vulnerability in WP Custom Cursors Project WP Custom Cursors
The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.
network
low complexity
wp-custom-cursors-project
7.2
2022-10-17 CVE-2022-3150 Unspecified vulnerability in WP Custom Cursors Project WP Custom Cursors
The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privileged users such as admin
network
low complexity
wp-custom-cursors-project
7.2