CVE-2022-2593: Better Search and Replace < 1.4.1 - Admin+ SQLi
Published Aug 22, 2022
·Updated
The Better Search Replace WordPress plugin before 1.4.1 does not properly sanitise and escape table data before inserting it into a SQL query, which could allow high privilege users to perform SQL Injection attacks
Affected Software
1 affected component
Deliciousbrains Better Search Replace Wordpress<1.4.1
Event History
Aug 22, 2022
CVE Published
via MITRE·03:04 PM
Data Sourced
via MITRE·03:04 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-2593?
CVE-2022-2593 has a medium severity rating due to its potential for SQL Injection attacks affecting high privilege users.
2
How do I fix CVE-2022-2593?
To fix CVE-2022-2593, update the Better Search Replace plugin to version 1.4.1 or later.
3
Who is affected by CVE-2022-2593?
CVE-2022-2593 affects users of the Better Search Replace WordPress plugin prior to version 1.4.1.
4
What type of vulnerability is CVE-2022-2593?
CVE-2022-2593 is classified as an SQL Injection vulnerability.
5
Can low privilege users exploit CVE-2022-2593?
CVE-2022-2593 can be exploited by high privilege users, making it less of a risk for low privilege users.