Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-57167
HistoryJun 22, 2022 - 12:00 a.m.

WordPress Better Find and Replace plugin SQL注入漏洞

2022-06-2200:00:00
China National Vulnerability Database
www.cnvd.org.cn
11
wordpress
find and replace
sql injection
vulnerability
attackers
php
sql statements

EPSS

0.001

Percentile

37.7%

WordPress and WordPress plugin are both products of the WordPress Foundation. WordPress is a set of blogging platforms developed using the PHP language. The WordPress plugin is an application plugin. versions prior to WordPress Better Find and Replace plugin 1.3.6 contain a SQL injection vulnerability that results from not properly cleaning, validating, and escaping various parameters before using them in SQL statements. and escape various parameters before use in SQL statements, which can be exploited by attackers to cause SQL injection.

EPSS

0.001

Percentile

37.7%