CVE-2022-1950: Youzify < 1.2.0 - Unauthenticated SQLi
The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1950?
CVE-2022-1950 is a vulnerability in the Youzify WordPress plugin before version 1.2.0 that allows unauthenticated users to perform an SQL injection attack.
How does CVE-2022-1950 affect the Youzify WordPress plugin?
CVE-2022-1950 affects the Youzify WordPress plugin before version 1.2.0 and allows unauthenticated users to exploit an SQL injection vulnerability.
What is the severity of CVE-2022-1950?
CVE-2022-1950 has a severity rating of 9.8 (Critical).
How can I fix CVE-2022-1950 in the Youzify WordPress plugin?
To fix CVE-2022-1950, it is recommended to update the Youzify WordPress plugin to version 1.2.0 or later.
Is there any additional information about CVE-2022-1950?
More information about CVE-2022-1950 can be found at: https://wpscan.com/vulnerability/4352283f-dd43-4827-b417-0c55d0f4637d