RSS   Vulnerabilities for 'Title experiments free'   RSS

2022-03-28
 
CVE-2022-0784

CWE-89
 

 
The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

 


Copyright 2024, cxsecurity.com

 

Back to Top