CVE-2022-4546
The Mapwiz WordPress plugin through 1.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
- Affected products
- Mapwiz Wordpress Plugin
- Conceptbeans Mapwiz
- ≤ 1.0.1
- Fix
- Available
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 1.0% (59th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2023-02-13
CVE-2022-4546 at NVD
1 known exploit for CVE-2022-4546
Proof-of-concept code and exploit modules indexed by Sploitus