← back
CVE-2022-0786observed exploitationCWE-89

KiviCare < 2.3.9 - Unauthenticated SQLi

45Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 13%
from disclosure to weapon
Published on NVDJun 13
VulnCheck+518d
exploitation probability
13%top 4% of all CVEs
observed exploitation
yesVulnCheck
The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users