CVE-2022-23911: AP Custom Testimonial < 1.4.8 - Admin+ SQL Injection
Published Feb 28, 2022
·Updated
The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection
Affected Software
1 affected component
Accesspressthemes Ap Custom Testimonial Wordpress<1.4.7
Event History
Feb 28, 2022
CVE Published
via MITRE·09:06 AM
Data Sourced
via MITRE·09:06 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-23911.
2
What is the affected software?
The affected software is the Testimonial WordPress Plugin version before 1.4.7.
3
What is the severity of CVE-2022-23911?
The severity of CVE-2022-23911 is high with a CVSS score of 7.2.
4
How can this vulnerability be exploited?
This vulnerability can be exploited through SQL injection.
5
How can I fix CVE-2022-23911?
To fix CVE-2022-23911, update the Testimonial WordPress Plugin to version 1.4.7 or later.