CVE-2022-3768
HIGH 8.8EPSS 3.7%
The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 3.66% chance of exploitation in the next 30 days, 89th percentile
- Nuclei
- high · CWE-89
- Published
- 2022-11-28
- Updated
- 2025-04-25
Proof-of-concept exploits (2)
- https://bulletin.iese.de/post/wp-smart-contracts_1-3-11/
- https://wpscan.com/vulnerability/1d8bf5bb-5a17-49b7-a5ba-5f2866e1f8a3