Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-19797
HistoryMar 09, 2022 - 12:00 a.m.

WordPress NotificationX Plugin SQL Injection Vulnerability

2022-03-0900:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
wordpress
notificationx plugin
sql injection
php
mysql
security vulnerability
data theft

EPSS

0.024

Percentile

90.0%

WordPress is the Wordpress Foundation’s set of blogging platforms developed using the PHP language. The platform supports personal blogging sites on PHP and MySQL servers. SQL injection vulnerability exists in versions prior to WordPress NotificationX Plugin 2.3.9, which stems from the plugin’s failure to clean and escape the nx_id parameter before using it in SQL statements. commands to steal sensitive database data.

EPSS

0.024

Percentile

90.0%