First published: Mon Aug 22 2022(Updated: )
The Better Search Replace WordPress plugin before 1.4.1 does not properly sanitise and escape table data before inserting it into a SQL query, which could allow high privilege users to perform SQL Injection attacks
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Better Search Replace | <1.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2593 has a medium severity rating due to its potential for SQL Injection attacks affecting high privilege users.
To fix CVE-2022-2593, update the Better Search Replace plugin to version 1.4.1 or later.
CVE-2022-2593 affects users of the Better Search Replace WordPress plugin prior to version 1.4.1.
CVE-2022-2593 is classified as an SQL Injection vulnerability.
CVE-2022-2593 can be exploited by high privilege users, making it less of a risk for low privilege users.