PT-2022-7031 · WordPress · Wordpress
Khuyenn
+1
·
Published
2022-01-06
·
Updated
2025-10-23
·
CVE-2022-21661
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WordPress versions prior to 5.8.3
WordPress versions 3.7.37 and earlier
Description
The issue is related to improper sanitization in the WP Query function of the WordPress content management system, which can lead to SQL injection through certain plugins or themes. This may allow a remote attacker to disclose stored credentials. The vulnerability has been patched in WordPress version 5.8.3 and older affected versions have also been fixed via security releases.
Recommendations
For WordPress versions prior to 5.8.3, update to version 5.8.3 or later to resolve the issue.
For WordPress versions 3.7.37 and earlier, update to version 3.7.37 or later to resolve the issue.
As a general mitigation measure, keep auto-updates enabled to ensure the latest security patches are applied.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordpress