Lucene search

K
cvelistWPScanCVELIST:CVE-2022-2460
HistoryAug 08, 2022 - 1:51 p.m.

CVE-2022-2460 WPDating < 7.4.0 - Multiple Unauthenticated SQLi

2022-08-0813:51:32
WPScan
www.cve.org
1
wpdating
sql injection
cve-2022-2460
unauthenticated users

AI Score

10

Confidence

High

EPSS

0.002

Percentile

57.5%

The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities exploitable by unauthenticated users

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "WPDating",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThan": "7.4.0"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

AI Score

10

Confidence

High

EPSS

0.002

Percentile

57.5%

Related for CVELIST:CVE-2022-2460