Lucene search

K
cvelistWPScanCVELIST:CVE-2022-0787
HistoryMar 28, 2022 - 5:23 p.m.

CVE-2022-0787 Limit Login Attempts (Spam Protection) < 5.1 - Unauthenticated SQLi

2022-03-2817:23:23
CWE-89
WPScan
www.cve.org
2
wordpress
plugin
sql injection

EPSS

0.044

Percentile

92.5%

The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections

CNA Affected

[
  {
    "product": "Limit Login Attempts (Spam Protection)",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "5.1",
        "status": "affected",
        "version": "5.1",
        "versionType": "custom"
      }
    ]
  }
]

EPSS

0.044

Percentile

92.5%