Description
The WP CSV Exporter WordPress plugin before 1.3.7 does not properly sanitise and escape some parameters before using them in a SQL statement, allowing high privilege users such as admin to perform SQL injection attacks
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-42655 | The WP CSV Exporter WordPress plugin before 1.3.7 does not properly sanitise and escape some parameters before using them in a SQL statement, allowing high privilege users such as admin to perform SQL injection attacks |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 23 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-23T15:06:38.699Z
Reserved: 2022-09-20T14:53:19.431Z
Link: CVE-2022-3249
Updated: 2024-08-03T01:07:05.559Z
Status : Modified
Published: 2022-12-05T17:15:09.880
Modified: 2025-04-23T16:15:23.717
Link: CVE-2022-3249
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD