The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2022-06-20T10:25:49

Updated: 2024-08-03T00:03:06.260Z

Reserved: 2022-04-26T00:00:00

Link: CVE-2022-1472

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-06-20T11:15:09.367

Modified: 2022-07-01T13:51:04.353

Link: CVE-2022-1472

cve-icon Redhat

No data.