PT-2022-21334 · WordPress · Blog2Social

Sakri Rafael Koskimies

·

Published

2022-10-25

·

Updated

2022-10-27

·

CVE-2022-3246

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Blog2Social: Social Media Auto Post & Scheduler WordPress plugin versions prior to 6.9.10
Description The issue is related to a SQL injection that occurs due to improper sanitization and escaping of a parameter used in a SQL statement. This can be exploited by any authenticated users, including subscribers.
Recommendations For versions prior to 6.9.10, update to version 6.9.10 or later to resolve the issue.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-3246

Affected Products

Blog2Social