First published: Mon Sep 19 2022(Updated: )
The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dylan James Zephyr Project Manager | <3.2.5 | |
Dylan James Zephyr Project Manager | <3.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2840 is classified as a critical SQL injection vulnerability affecting the Zephyr Project Manager WordPress plugin.
To fix CVE-2022-2840, update the Zephyr Project Manager plugin to version 3.2.5 or later.
CVE-2022-2840 affects all users of the Zephyr Project Manager WordPress plugin versions prior to 3.2.5.
Exploiting CVE-2022-2840 could allow attackers to execute arbitrary SQL queries, potentially compromising the database.
Versions of the Zephyr Project Manager plugin before 3.2.5 are vulnerable to CVE-2022-2840.