Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-03187
HistoryJan 08, 2022 - 12:00 a.m.

WordPress WP_Query SQL Injection Vulnerability

2022-01-0800:00:00
China National Vulnerability Database
www.cnvd.org.cn
69

0.934 High

EPSS

Percentile

99.1%

WordPress is the WordPress Foundation’s set of blogging platforms developed using the PHP language. The platform supports personal blog sites on PHP and MySQL servers.WordPress has a SQL injection vulnerability in versions prior to 5.8.3, which stems from the lack of validation of externally entered SQL statements in WP_Query. An attacker could use this vulnerability to execute illegal SQL commands to steal sensitive database data.

CPENameOperatorVersion
wordpress wordpresslt5.8.3