CVE-2022-45355: WordPress WP Pipes Plugin <= 1.33 is vulnerable to SQL Injection (SQLi)
Published Mar 29, 2023
·Updated
Auth. (admin+) SQL Injection (SQLi) vulnerability in ThimPress WP Pipes plugin <= 1.33 versions.
Affected Software
1 affected component
Thimpress WP Pipes<=1.33
Remediation
Information
Update to 1.4.0 or a higher version.
Event History
Mar 29, 2023
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-45355?
CVE-2022-45355 is an authentication (admin+) SQL Injection (SQLi) vulnerability in the ThimPress WP Pipes plugin version 1.33 and earlier.
2
How severe is CVE-2022-45355?
CVE-2022-45355 has a severity rating of 7.2, which is considered high.
3
Which software versions are affected by CVE-2022-45355?
CVE-2022-45355 affects ThimPress WP Pipes plugin versions up to and including 1.33.
4
What is the Common Vulnerabilities and Exposures (CVE) ID for this vulnerability?
The Common Vulnerabilities and Exposures (CVE) ID for this vulnerability is CVE-2022-45355.
5
How can I fix CVE-2022-45355?
To fix CVE-2022-45355, update your ThimPress WP Pipes plugin to version 1.34 or later.