ZeroHour

CVE-2022-1013

PoC
CVSS 3.1
9.8 critical
EPSS
8%p94
Published
()
Modified
Description

The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability.

Vendors
ays-pro
Products
personal dictionary
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.