CVE-2022-0788
WP Fundraising Donation and Crowdfunding Platform < 1.5.0 - Unauthenticated SQLi
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a parameter before using it in a SQL statement via one of it's REST route, leading to an SQL injection exploitable by unauthenticated users
El plugin WP Fundraising Donation and Crowdfunding Platform WordPress anterior a la versión 1.5.0 no sanea y escapa de un parámetro antes de utilizarlo en una sentencia SQL a través de una de sus rutas REST, lo que lleva a una inyección SQL explotable por usuarios no autentificados
The WP Fundraising Donation and Crowdfunding Platform WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via one of it's REST route, leading to an SQL injection exploitable by unauthenticated users
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-28 CVE Reserved
- 2022-05-11 CVE Published
- 2024-06-02 EPSS Updated
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/fbc71710-123f-4c61-9796-a6a4fd354828 | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wpmet Search vendor "Wpmet" | Wp Fundraising Donation And Crowdfunding Platform Search vendor "Wpmet" for product "Wp Fundraising Donation And Crowdfunding Platform" | < 1.5.0 Search vendor "Wpmet" for product "Wp Fundraising Donation And Crowdfunding Platform" and version " < 1.5.0" | wordpress |
Affected
|