PoC Index

CVE-2022-4099

CRITICAL 9.8EPSS 1.0%

The Joy Of Text Lite WordPress plugin before 2.3.1 does not properly sanitise and escape some parameters before using them in SQL statements accessible to unauthenticated users, leading to unauthenticated SQL injection

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.04% chance of exploitation in the next 30 days, 62th percentile
Published
2023-01-02
Updated
2025-04-10

Proof-of-concept exploits (1)

References

Related