First published: Mon Aug 01 2022(Updated: )
The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
KaineLabs Youzify | <1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1950 is a vulnerability in the Youzify WordPress plugin before version 1.2.0 that allows unauthenticated users to perform an SQL injection attack.
CVE-2022-1950 affects the Youzify WordPress plugin before version 1.2.0 and allows unauthenticated users to exploit an SQL injection vulnerability.
CVE-2022-1950 has a severity rating of 9.8 (Critical).
To fix CVE-2022-1950, it is recommended to update the Youzify WordPress plugin to version 1.2.0 or later.
More information about CVE-2022-1950 can be found at: https://wpscan.com/vulnerability/4352283f-dd43-4827-b417-0c55d0f4637d