CVE-2022-47614: WordPress MStore API Plugin <= 3.9.7 is vulnerable to SQL Injection
Published Jun 23, 2023
·Updated
Unauth. SQL Injection (SQLi) vulnerability in InspireUI MStore API plugin <= 3.9.7 versions.
Affected Software
1 affected component
InspireUI Mstore Api Wordpress<=3.9.7
Remediation
Information
Update to 3.9.8 or a higher version.
Event History
Jun 23, 2023
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the Unauthenticated SQL Injection (SQLi) vulnerability in the InspireUI MStore API plugin?
The vulnerability ID is CVE-2022-47614.
2
What is the severity of CVE-2022-47614?
The severity of CVE-2022-47614 is high with a CVSS score of 7.5.
3
What is affected by the Unauthenticated SQL Injection (SQLi) vulnerability in the InspireUI MStore API plugin?
Versions of InspireUI MStore API plugin up to and including 3.9.7 are affected.
4
How can I fix the Unauthenticated SQL Injection (SQLi) vulnerability in the InspireUI MStore API plugin?
To fix the vulnerability, update the InspireUI MStore API plugin to version 3.9.8 or later.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-47614?
The CWE ID for CVE-2022-47614 is CWE-89.