CVE-2022-0773

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
02/05/2022
Last modified:
09/05/2022

Description

The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:documentor_project:documentor:*:*:*:*:*:wordpress:*:* 1.5.3 (including)