The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-06-20T10:25:49

Updated: 2022-06-20T10:25:49

Reserved: 2022-04-26T00:00:00


Link: CVE-2022-1472

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-06-20T11:15:09.367

Modified: 2022-07-01T13:51:04.353


Link: CVE-2022-1472

JSON object: View

cve-icon Redhat Information

No data.

CWE