← back
CVE-2022-0827observed exploitationCWE-89

Bestbooks <= 2.6.3 - Unauthenticated SQLi

40Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 9.0%
from disclosure to weapon
Published on NVDJun 13
VulnCheck+535d
exploitation probability
9.0%top 5% of all CVEs
observed exploitation
yesVulnCheck
The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users
Affected products
Unknown · Bestbooks