CVE-2022-0254
14.03.2022, 15:15
The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection
Vendor | Product | Version |
---|---|---|
highfivery | zero-spam | 𝑥 < 5.2.11 |
𝑥
= Vulnerable software versions
References