CVE-2022-0760: Simple Link Directory < 7.7.2 - Unauthenticated SQL injection
The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the postid parameter before using it in a SQL statement via the qcopdupvoteaction AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-0760?
CVE-2022-0760 is a vulnerability in the Simple Link Directory WordPress plugin before version 7.7.2.
How does CVE-2022-0760 affect the Simple Link Directory plugin?
CVE-2022-0760 allows unauthenticated and authenticated users to perform an SQL injection attack by exploiting the qcopd_upvote_action AJAX action.
What is the severity of CVE-2022-0760?
CVE-2022-0760 has a severity rating of 9.8 (Critical).
How can I fix CVE-2022-0760?
To fix CVE-2022-0760, upgrade to version 7.7.2 or later of the Simple Link Directory plugin.
Where can I find more information about CVE-2022-0760?
More information about CVE-2022-0760 can be found at the following references: - [https://plugins.trac.wordpress.org/changeset/2684915](https://plugins.trac.wordpress.org/changeset/2684915) - [https://wpscan.com/vulnerability/1c83ed73-ef02-45c0-a9ab-68a3468d2210](https://wpscan.com/vulnerability/1c83ed73-ef02-45c0-a9ab-68a3468d2210)