CVE-2022-3981: Icegram Express < 5.5.1 - Subscriber+ SQLi
Published Dec 12, 2022
·Updated
The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscriber
Affected Software
1 affected component
Icegram Email Subscribers \& Newsletters Wordpress<5.5.1
Event History
Dec 12, 2022
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-3981.
2
What is the severity of CVE-2022-3981?
The severity of CVE-2022-3981 is high.
3
What does CVE-2022-3981 affect?
CVE-2022-3981 affects the Icegram Express WordPress plugin before version 5.5.1.
4
How can CVE-2022-3981 be exploited?
CVE-2022-3981 can be exploited by any authenticated users, such as subscribers, through a SQL injection.
5
Is there a fix available for CVE-2022-3981?
Yes, a fix is available for CVE-2022-3981 in version 5.5.1 of the Icegram Express WordPress plugin.