First published: Mon May 09 2022(Updated: )
The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ays-pro Personal Dictionary | <1.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1013 is a blind SQL injection vulnerability in the Personal Dictionary WordPress plugin before version 1.3.4.
CVE-2022-1013 has a severity rating of 9.8 (critical).
The Ays-pro Personal Dictionary WordPress plugin version up to 1.3.4 is affected by CVE-2022-1013.
To fix CVE-2022-1013, update the Personal Dictionary WordPress plugin to version 1.3.4 or later.
CWE-89 is a weakness category called 'Improper Neutralization of Special Elements used in an SQL Command.'