CVE-2022-0267
The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection
- Affected products
- Adrotate
- Adrotate Project Adrotate
- < 5.8.22
- Fix
- Available
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 1.3% (67th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2022-03-07
CVE-2022-0267 at NVD
1 known exploit for CVE-2022-0267
Proof-of-concept code and exploit modules indexed by Sploitus