Sploitus

CVE-2022-4357

1 known exploit for CVE-2022-4357

The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

Affected products
Letsrecover
Letsrecover Project Letsrecover
≤ 1.1.0
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
1.0% (60th percentile)
NVD status
Modified
Published
2023-01-02
CVE-2022-4357 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2022-4357

Proof-of-concept code and exploit modules indexed by Sploitus