CyberRota Analysis
AI-GeneratedThe sm page duplicator plugin for WordPress versions up to 1.0.0 is vulnerable to SQL Injection due to insufficient sanitization of stored values in SQL statements during page duplication. This flaw allows users with Editor privileges and higher to manipulate database queries, potentially leading to unauthorized data access or modification. WordPress site administrators and developers using this plugin should prioritize immediate updates to mitigate the risk of exploitation.
Original NVD Description
The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating a page, allowing users with the Editor role and above to perform SQL Injection attacks.