CVE-2022-1023: Podcast Importer SecondLine < 1.3.8 - Admin+ SQLi
Published Apr 11, 2022
·Updated
The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file
Affected Software
1 affected component
SecondLineThemes Podcast Importer Secondline Wordpress<1.3.8
Remediation
Patch Available
Event History
Apr 11, 2022
CVE Published
via MITRE·02:41 PM
Data Sourced
via MITRE·02:41 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the Podcast Importer SecondLine WordPress plugin?
The vulnerability ID for the Podcast Importer SecondLine WordPress plugin is CVE-2022-1023.
2
What is the severity of CVE-2022-1023?
The severity of CVE-2022-1023 is high, with a severity value of 7.2.
3
What is the affected software for CVE-2022-1023?
The affected software for CVE-2022-1023 is the Secondlinethemes Podcast Importer Secondline WordPress plugin before version 1.3.8.
4
What is the risk of CVE-2022-1023?
CVE-2022-1023 poses a risk of SQL injection attacks through imported malicious podcast files.
5
How can I fix CVE-2022-1023?
To fix CVE-2022-1023, update your Secondlinethemes Podcast Importer Secondline plugin to version 1.3.8 or higher.