HIGH
WPSmartContracts < 1.3.12 - Author+ SQLi
Published Nov 28, 2022
8.8
HIGHCVSS 3.1
EPSS 3.99%
Description
The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author
Affected products
- Vendor n/a Product WPSmartContracts Defaultunaffected
- Version 0StatusaffectedConstraints<1.3.12
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | WPSmartContracts | unaffected |
|
- < 1.3.12
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://bulletin.iese.de/post/wp-smart-contracts_1-3-11/ ExploitThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43120 Advisory
- https://wpscan.com/vulnerability/1d8bf5bb-5a17-49b7-a5ba-5f2866e1f8a3 exploitvdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://bulletin.iese.de/post/wp-smart-contracts_1-3-11/ | ExploitThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43120 | Advisory | |
| https://wpscan.com/vulnerability/1d8bf5bb-5a17-49b7-a5ba-5f2866e1f8a3 | exploitvdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Nov 28, 2022
Updated Apr 25, 2025
Reserved Oct 31, 2022
Link CVE-2022-3768
CISA Vulnrichment
Updated Apr 25, 2025
ENISA EUVD
EUVD-2022-43120 Assigner WPScan
Published Nov 28, 2022
Updated Apr 25, 2025
Exploited since n/a
Link EUVD-2022-43120