← volver
CVE-2022-0784explotación observadaCWE-89

Title Experiments Free < 9.0.1 - Unauthenticated SQLi

45Vexday Risk Score

Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.

ssvc Actepss 10%
de la publicación al arma
Publicada en NVD28 mar
VulnCheck+609d
probabilidad de explotación
10%top 5% de las CVE
explotación observada
VulnCheck
The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection