The WPDating WordPress plugin through 7.1.9 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/694b6dfd-2424-41b4-8595-b6c305c390db | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-08-08 07:15
Updated : 2022-08-12 07:33
NVD link : CVE-2022-2460
Mitre link : CVE-2022-2460
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
digital_product_labs
- wpdating