The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/62803aae-9896-410b-9398-3497a838e494 | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: WPScan
Published: 2022-05-16T14:30:29
Updated: 2022-05-16T14:30:29
Reserved: 2022-03-04T00:00:00
Link: CVE-2022-0867
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-05-16T15:15:08.657
Modified: 2022-05-24T20:26:20.100
Link: CVE-2022-0867
JSON object: View
Redhat Information
No data.
CWE