Vulnerability CVE-2022-1556


Published: 2022-05-30

Description:
The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection

Type:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

 References:
https://packetstormsecurity.com/files/166918/
https://wpscan.com/vulnerability/04890549-6bd1-44dd-8bce-7125c01be5d4

Copyright 2026, cxsecurity.com

 

Back to Top