CVE-2022-4357
The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
- Affected products
- Letsrecover
- Letsrecover Project Letsrecover
- ≤ 1.1.0
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 1.0% (60th percentile)
- NVD status
- Modified
- Published
- 2023-01-02
CVE-2022-4357 at NVD
1 known exploit for CVE-2022-4357
Proof-of-concept code and exploit modules indexed by Sploitus