CVE-2022-4297
02.01.2023, 22:15
The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX available to unauthenticated users, leading to an unauthenticated SQL injectionEnginsight
Vendor | Product | Version |
---|---|---|
netflixtech | wp_autocomplete_search | 𝑥 ≤ 1.0.4 |
𝑥
= Vulnerable software versions
References