CVE-2022-0254
EUVD-2022-150014.03.2022, 15:15
The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| highfivery | zero-spam | 𝑥 < 5.2.11 |
𝑥
= Vulnerable software versions
References