← back
CVE-2022-1013

Personal Dictionary < 1.3.4 - Unauthenticated SQLi

EPSS 6.6%CWE-89
The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →