๐Ÿ” CVE Alert

CVE-2023-28748

CRITICAL 9.8

WordPress Copy Or Move Comments Plugin <= 5.0.4 is vulnerable to SQL Injection

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in biztechc Copy or Move Comments allows SQL Injection.This issue affects Copy or Move Comments: from n/a through 5.0.4.

CWE CWE-89
Vendor biztechc
Product copy or move comments
Published Nov 6, 2023
Last Updated Apr 28, 2026
Stay Ahead of the Next One

Get instant alerts for biztechc copy or move comments

Be the first to know when new critical vulnerabilities affecting biztechc copy or move comments are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

biztechc / Copy or Move Comments
n/a โ‰ค 5.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/vulnerability/copy-or-move-comments/wordpress-copy-or-move-comments-plugin-5-0-4-sql-injection-vulnerability?_s_id=cve

Credits

minhtuanact (Patchstack Alliance)