CVE-2022-3246: Blog2Social < 6.9.10 - Subscriber+ SQLi
Published Oct 25, 2022
·Updated
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers
Affected Software
1 affected component
Adenion Blog2social Wordpress<6.9.10
Event History
Oct 25, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-3246?
CVE-2022-3246 is a vulnerability in the Blog2Social WordPress plugin that allows SQL injection attacks by authenticated users.
2
What is the severity of CVE-2022-3246?
The severity of CVE-2022-3246 is high with a CVSS score of 8.8.
3
Who is affected by CVE-2022-3246?
The Blog2Social plugin versions prior to 6.9.10 are affected by CVE-2022-3246.
4
How can an attacker exploit CVE-2022-3246?
An attacker can exploit CVE-2022-3246 by exploiting the SQL injection vulnerability in the Blog2Social plugin.
5
How can I fix CVE-2022-3246?
To fix CVE-2022-3246, update the Blog2Social plugin to version 6.9.10 or later.