← back
CVE-2022-0785observed exploitationCWE-89

Daily Prayer Time < 2022.03.01 - Unauthenticated SQLi

40Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 9.1%
from disclosure to weapon
Published on NVDApr 18
VulnCheck+1422d
exploitation probability
9.1%top 5% of all CVEs
observed exploitation
yesVulnCheck
The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection