PoC Index

CVE-2022-0773

CRITICAL 9.8EPSS 43.3%

The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
43.26% chance of exploitation in the next 30 days, 99th percentile
Nuclei
critical · CWE-89
Published
2022-05-02
Updated
2024-08-02

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related