PT-2022-13182 · WordPress · Page View Count

Krzysztof Zając

·

Published

2022-03-07

·

Updated

2022-03-11

·

CVE-2022-0434

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Page View Count WordPress plugin versions prior to 2.4.15
Description The issue allows unauthenticated attackers to perform SQL injection attacks due to the lack of sanitization and escaping of the post ids parameter in a SQL statement via a REST endpoint. This endpoint is accessible to both unauthenticated and authenticated users.
Recommendations For versions prior to 2.4.15, update to version 2.4.15 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST endpoint until the update is applied. Avoid using the post ids parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0434

Affected Products

Page View Count