CVE-2022-0420: RegistrationMagic < 5.0.2.2 - Admin+ SQL Injection
The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rmformid parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-0420?
CVE-2022-0420 is a vulnerability in the RegistrationMagic WordPress plugin that allows high privilege users to perform SQL injection attacks.
How does CVE-2022-0420 affect the RegistrationMagic plugin?
CVE-2022-0420 affects the RegistrationMagic plugin before version 5.0.2.2.
What is the severity of CVE-2022-0420?
CVE-2022-0420 has a severity keyword of "high" and a severity value of 7.2.
How can high privilege users exploit CVE-2022-0420?
High privilege users can exploit CVE-2022-0420 by performing SQL injection attacks using the rm_form_id parameter in a SQL statement in the Automation admin dashboard.
Are there any references for CVE-2022-0420?
Yes, you can find references for CVE-2022-0420 at the following URLs: [https://plugins.trac.wordpress.org/changeset/2672042](https://plugins.trac.wordpress.org/changeset/2672042) and [https://wpscan.com/vulnerability/056b5167-3cbc-47d1-9917-52a434796151](https://wpscan.com/vulnerability/056b5167-3cbc-47d1-9917-52a434796151).