← back
CVE-2022-0434observed exploitationCWE-89

Page Views Count < 2.4.15 - Unauthenticated SQL Injection

45Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 15%
from disclosure to weapon
Published on NVDMar 7
VulnCheck+1188d
exploitation probability
15%top 4% of all CVEs
observed exploitation
yesVulnCheck
The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks