ZeroHour

CVE-2022-2460

PoC
CVSS 3.1
9.8 critical
EPSS
1%p64
Published
()
Modified
Description

The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities exploitable by unauthenticated users

Vendors
digital product labs
Products
wpdating
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.