Multiple SQL Injection Vulnerabilities in WPDating WordPress Plugin (Before 7.4.0)
CVE-2022-2460 · CRITICAL Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities exploitable by unauthenticated users
Learn more about our Wordpress Pen Testing.