Description
The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX available to unauthenticated users, leading to an unauthenticated SQL injection
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-51653 | The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX available to unauthenticated users, leading to an unauthenticated SQL injection |
References
History
Fri, 11 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-11T13:39:48.376Z
Reserved: 2022-12-06T09:10:24.775Z
Link: CVE-2022-4297
Updated: 2024-08-03T01:34:49.994Z
Status : Modified
Published: 2023-01-02T22:15:16.813
Modified: 2025-04-11T14:15:22.570
Link: CVE-2022-4297
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD