logo

CVE-2022-0254 bmarshall511/wordpress_zero_spam

Package

Manager: composer
Name: bmarshall511/wordpress_zero_spam
Vulnerable Version: >=0 <5.2.13

Severity

Level: Critical

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00924 pctl0.75136

Details

SQL Injection in WordPress Zero Spam WordPress plugin The WordPress Zero Spam WordPress plugin before 5.2.13 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection

Metadata

Created: 2022-03-15T00:00:57Z
Modified: 2022-03-29T15:26:17Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-pq2f-3fg3-rw99/GHSA-pq2f-3fg3-rw99.json
CWE IDs: ["CWE-89"]
Alternative ID: GHSA-pq2f-3fg3-rw99
Finding: F297
Auto approve: 1