CVE-2022-21664: high-severity vulnerability in wordpress-develop
SQL injection in WordPress
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.4epss 3.8%
exploitation probability
3.8%top 10% of all CVEs
observed exploitation
nono source reports it
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 4.1.34. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Affected products
WordPress · wordpress-developRelated CVEs — wordpress-develop
In the same product, most dangerous first.
CVE-2022-21661HIGHSQL injection in WordPressEPSS 97.8%CVE-2021-29447HIGHWordPress Authenticated XXE attack when installation is running PHP 8EPSS 85.7%CVE-2022-21662HIGHStored XSS in WordPressEPSS 64.5%CVE-2022-21663MEDIUMAuthenticated Object Injection in Multisites in WordPressEPSS 3.7%CVE-2020-4047MEDIUMAuthenticated XSS via media attachment page in WordPressEPSS 3.3%CVE-2024-31211MEDIUMRemote Code Execution in `WP_HTML_Token`EPSS 2.8%
References
https://github.com/WordPress/wordpress-develop/commit/c09ccfbc547d75b392dbccc1ef0b4442ccd3c957https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-jp3p-gw8h-6x86https://lists.debian.org/debian-lts-announce/2022/01/msg00019.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV4UNEC63UU5GEU47IIR4RMTZAHNEOJG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DM6XPH3JN6V4NF4WBOJTOXZIVE6VKKE3/https://wordpress.org/news/2022/01/wordpress-5-8-3-security-release/https://www.debian.org/security/2022/dsa-5039