CVE-2022-0349: NotificationX < 2.3.9 - Unauthenticated Blind SQL Injection
Published Mar 7, 2022
·Updated
The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nxid parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection
Affected Software
1 affected component
WPDeveloper Notificationx Wordpress<2.3.9
Event History
Mar 7, 2022
CVE Published
via MITRE·08:16 AM
Data Sourced
via MITRE·08:16 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-0349?
The severity of CVE-2022-0349 is critical with a score of 9.8.
2
Which software is affected by CVE-2022-0349?
The NotificationX WordPress plugin versions up to 2.3.9 are affected by CVE-2022-0349.
3
What is the vulnerability type of CVE-2022-0349?
CVE-2022-0349 is an Unauthenticated Blind SQL Injection vulnerability.
4
How can I fix CVE-2022-0349?
To fix CVE-2022-0349, update the NotificationX WordPress plugin to version 2.3.9 or higher.
5
Where can I find more information about CVE-2022-0349?
More information about CVE-2022-0349 can be found at the following reference: https://wpscan.com/vulnerability/1d0dd7be-29f3-4043-a9c6-67d02746463a