ZeroHour

CVE-2022-0773

PoC
CVSS 3.1
9.8 critical
EPSS
43%p99
Published
()
Modified
Description

The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users.

Vendors
documentor project
Products
documentor
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.