CVE-2022-1013: Personal Dictionary < 1.3.4 - Unauthenticated SQLi
Published May 9, 2022
·Updated
The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability.
Affected Software
1 affected component
ays-pro Personal Dictionary Wordpress<1.3.4
Event History
May 9, 2022
CVE Published
via MITRE·04:50 PM
Data Sourced
via MITRE·04:50 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-1013?
CVE-2022-1013 is a blind SQL injection vulnerability in the Personal Dictionary WordPress plugin before version 1.3.4.
2
How severe is CVE-2022-1013?
CVE-2022-1013 has a severity rating of 9.8 (critical).
3
Which software is affected by CVE-2022-1013?
The Ays-pro Personal Dictionary WordPress plugin version up to 1.3.4 is affected by CVE-2022-1013.
4
How can I fix CVE-2022-1013?
To fix CVE-2022-1013, update the Personal Dictionary WordPress plugin to version 1.3.4 or later.
5
What is CWE-89?
CWE-89 is a weakness category called 'Improper Neutralization of Special Elements used in an SQL Command.'