CVE-2022-3254: AWP Classifieds Plugin < 4.3 - Unauthenticated SQLi
Published Oct 31, 2022
·Updated
The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection
Affected Software
2 affected components
Awpcp Another Wordpress Classifieds Plugin Wordpress<4.3
Strategy11 Awp Classifieds Wordpress<4.3
Event History
Oct 31, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-3254?
The severity of CVE-2022-3254 is critical.
2
How does CVE-2022-3254 affect WordPress Classifieds Plugin?
CVE-2022-3254 affects the WordPress Classifieds Plugin version before 4.3.
3
What is the impact of CVE-2022-3254?
CVE-2022-3254 can lead to SQL injection.
4
How can I fix CVE-2022-3254?
To fix CVE-2022-3254, update the WordPress Classifieds Plugin to version 4.3 or later.
5
Is CVE-2022-3254 exploitable by unauthenticated users?
Yes, CVE-2022-3254 can be exploited by unauthenticated users.