CVE-2022-0786: KiviCare < 2.3.9 - Unauthenticated SQLi
The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajaxpost AJAX action with the getdoctordetails route, leading to SQL Injections exploitable by unauthenticated users
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-0786?
CVE-2022-0786 is a vulnerability in the KiviCare WordPress plugin before version 2.3.9 that allows SQL injection attacks by unauthenticated users.
How severe is CVE-2022-0786?
CVE-2022-0786 has a severity rating of 9.8 (critical).
Which software versions are affected by CVE-2022-0786?
The KiviCare WordPress plugin versions up to and excluding 2.3.9 are affected by CVE-2022-0786.
How can CVE-2022-0786 be exploited?
Unauthenticated users can exploit CVE-2022-0786 by performing SQL injection attacks via the ajax_post AJAX action with the get_doctor_details route.
Is there a fix available for CVE-2022-0786?
Yes, upgrading to version 2.3.9 of the KiviCare WordPress plugin will fix CVE-2022-0786.