First published: Mon Sep 19 2022(Updated: )
The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
BadgeOS | <3.7.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2958 is classified as a high severity vulnerability due to the potential for SQL injection attacks.
To fix CVE-2022-2958, update the BadgeOS WordPress plugin to version 3.7.1.3 or later.
If unpatched, CVE-2022-2958 allows authenticated users to perform SQL injection attacks, potentially compromising the database.
CVE-2022-2958 affects users of the BadgeOS WordPress plugin versions prior to 3.7.1.3.
CVE-2022-2958 enables SQL injection attacks through un-sanitized parameters in AJAX actions.