Multiple SQL Injection Vulnerabilities in WPDating WordPress Plugin (Before 7.4.0)

Multiple SQL Injection Vulnerabilities in WPDating WordPress Plugin (Before 7.4.0)

CVE-2022-2460 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities exploitable by unauthenticated users

Learn more about our Wordpress Pen Testing.