Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') (CWE-90)
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for unauthenticated attackers to extract potentially sensitive information from the LDAP directory.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Feedly found the first article mentioning CVE-2023-3447. See article
The CVE-2023-3447 vulnerability in the Active Directory Integration / LDAP Integration plugin for WordPress allows unauthenticated attackers to perform LDAP Injection, potentially extracting sensitive information from the LDAP directory. With a CVSS score of 8.6, this critical vulnerability poses a significant risk if exploited in the wild. Mitigations include updating to version 4.1.6 or higher, and organizations should monitor for any signs of exploitation or unauthorized access to LDAP directories. See article