CVE-2022-0782

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
25/04/2022
Last modified:
03/05/2022

Description

The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_validate_fields_php_function AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:donations_project:donations:*:*:*:*:*:wordpress:*:* 1.8 (including)