CVE-2022-0787: Limit Login Attempts (Spam Protection) < 5.1 - Unauthenticated SQLi
The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-0787?
CVE-2022-0787 is a vulnerability found in the Limit Login Attempts (Spam Protection) WordPress plugin before version 5.1, which allows unauthenticated users to perform SQL injection attacks.
How severe is CVE-2022-0787?
CVE-2022-0787 has a severity rating of 9.8, making it a critical vulnerability.
What is the affected software?
The affected software is the Limit Login Attempts (Spam Protection) WordPress plugin version up to 5.1.
What is the CWE of CVE-2022-0787?
The CWE (Common Weakness Enumeration) of CVE-2022-0787 is 89, which is related to SQL injection vulnerabilities.
How can I fix CVE-2022-0787?
To fix CVE-2022-0787, you should update the Limit Login Attempts (Spam Protection) WordPress plugin to version 5.1 or newer.