ZeroHour

CVE-2022-0771

PoC
CVSS 3.1
9.8 critical
EPSS
2%p74
Published
()
Modified
Description

The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections

Vendors
marketingheroes
Products
sitesupercharger
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.