PT-2022-15653 · WordPress · Simple Quotation

Abhishek Bhoir

·

Published

2022-03-14

·

Updated

2022-03-21

·

CVE-2022-22735

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Simple Quotation WordPress plugin versions 1.3.2 and earlier
Description The issue concerns a lack of authorization and CSRF checks in various AJAX actions, as well as insufficient escaping of user data in SQL statements. This allows any authenticated user to perform SQL injection attacks.
Recommendations For versions 1.3.2 and earlier, update to a version that includes proper authorization checks and user data escaping in SQL statements to prevent SQL injection attacks.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-22735

Affected Products

Simple Quotation