PT-2022-7031 · WordPress · Wordpress

Khuyenn

+1

·

Published

2022-01-06

·

Updated

2025-10-23

·

CVE-2022-21661

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WordPress versions prior to 5.8.3 WordPress versions 3.7.37 and earlier
Description The issue is related to improper sanitization in the WP Query function of the WordPress content management system, which can lead to SQL injection through certain plugins or themes. This may allow a remote attacker to disclose stored credentials. The vulnerability has been patched in WordPress version 5.8.3 and older affected versions have also been fixed via security releases.
Recommendations For WordPress versions prior to 5.8.3, update to version 5.8.3 or later to resolve the issue. For WordPress versions 3.7.37 and earlier, update to version 3.7.37 or later to resolve the issue. As a general mitigation measure, keep auto-updates enabled to ensure the latest security patches are applied.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2023-07191
BIT-WORDPRESS-2022-21661
BIT-WORDPRESS-MULTISITE-2022-21661
CVE-2022-21661
DLA-2884-1
DSA-5039-1
GHSA-6676-CQFM-GW84
ZDI-22-020

Affected Products

Wordpress