CVE-2022-3395

The WP All Export Pro WordPress plugin before 1.7.9 uses the contents of the cc_sql POST parameter directly as a database query, allowing users which has been given permission to run exports to execute arbitrary SQL statements, leading to a SQL Injection vulnerability. By default only users with the Administrator role can perform exports, but this can be delegated to lower privileged users as well.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:soflyy:wp_all_export:*:*:*:*:pro:wordpress:*:*

Information

Published : 2022-10-25 10:15

Updated : 2022-10-26 08:11


NVD link : CVE-2022-3395

Mitre link : CVE-2022-3395


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

soflyy

  • wp_all_export