CVE-2022-4297
WP AutoComplete Search <= 1.0.4 - Unauthenticated SQLi
The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX available to unauthenticated users, leading to an unauthenticated SQL injection
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · WP AutoComplete Searchpublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/173293/WordPress-WP-AutoComplete-Search-1.0.4-SQL-Injection.htmlunverifiedcve_referencewpscan.com/vulnerability/e2dcc76c-65ac-4cd6-a5c9-6d813b5ac26dunverifiedexploitdbwww.exploit-db.com/exploits/51560unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →