CVE-2022-3249

CVSS V2 None CVSS V3 None
Description
The WP CSV Exporter WordPress plugin before 1.3.7 does not properly sanitise and escape some parameters before using them in a SQL statement, allowing high privilege users such as admin to perform SQL injection attacks
Overview
  • CVE ID
  • CVE-2022-3249
  • Assigner
  • contact@wpscan.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-12-05T17:15:09.880
  • Last Modified Date
  • 2022-12-06T17:34:33.867
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:wp_csv_exporter_project:wp_csv_exporter:*:*:*:*:*:wordpress:*:* 1 OR 1.3.7
References
Reference URL Reference Tags
https://wpscan.com/vulnerability/6503da78-a2bf-4b4c-b56d-21c8c55b076e Exploit Third Party Advisory
History
Created Old Value New Value Data Type Notes
2022-12-07 18:06:34 Added to TrackCVE