Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-62805
HistoryFeb 18, 2022 - 12:00 a.m.

WordPress plugin Fancy Product Designer SQL injection vulnerability

2022-02-1800:00:00
China National Vulnerability Database
www.cnvd.org.cn
10

0.001 Low

EPSS

Percentile

29.8%

WordPress is a set of blogging platforms developed using the PHP language by the WordPress (Wordpress) Foundation. The platform supports setting up personal blog sites on servers with PHP and MySQL. SQL injection vulnerability exists in the WordPress plugin Fancy Product Designer 4.7.4 and earlier, which stems from insufficient escaping and parameterization of the ID parameter in the ~inc api class-view.php file. An attacker could use this vulnerability to inject arbitrary SQL queries to obtain sensitive information.

0.001 Low

EPSS

Percentile

29.8%

Related for CNVD-2022-62805