CVE Feed

    Dashboard / CVE / CVE-2022-0693

    CVE-2022-0693

    The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL Injection

    Published:Apr 25, 2022
    Last Modified:Nov 21, 2024
    EPS:Apr 25, 2022
    EPSS Score:0.60172
    CVSS Score:9.8

    Affected Products

    Vendor
    Devbunch
    Product
    Master Elements

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High