CVE-2022-3302: Anti-Spam by CleanTalk < 5.185.1 - Admin+ SQLi
Published Oct 25, 2022
·Updated
The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using them in a SQL statement, which could lead to SQL injection exploitable by high privilege users such as admin
Affected Software
1 affected component
CleanTalk Spam Protection\, Antispam\, Firewall Wordpress<5.185.1
Event History
Oct 25, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-3302.
2
What is the title of the vulnerability?
The title of the vulnerability is 'The Spam protection AntiSpam FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate…'
3
What is the severity of CVE-2022-3302?
The severity of CVE-2022-3302 is high (7.2).
4
What is the affected software of CVE-2022-3302?
The affected software of CVE-2022-3302 is the Spam protection AntiSpam FireWall by CleanTalk WordPress plugin before version 5.185.1.
5
How can this vulnerability be exploited?
This vulnerability can be exploited through SQL injection by high privilege users such as admin.