← back
CVE-2022-2958observed exploitationCWE-89

BadgeOS < 3.7.1.3 - Subscriber+ SQLi

25Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendepss 1.1%
from disclosure to weapon
Published on NVDSep 19
VulnCheck+424d
exploitation probability
1.1%top 39% of all CVEs
observed exploitation
yesVulnCheck
The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections
Affected products
Unknown · BadgeOS