The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by high privilege users such as admin by default. However, depending on the plugin configuration, other users, such as subscriber could exploit this as well
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2023-01-02T21:49:39.886Z

Updated: 2023-01-10T09:09:05.928Z

Reserved: 2022-12-09T03:21:34.993Z


Link: CVE-2022-4372

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-01-02T22:15:17.927

Modified: 2023-11-07T03:57:40.893


Link: CVE-2022-4372

JSON object: View

cve-icon Redhat Information

No data.

CWE

No CWE.