SQL Injection Vulnerability in BadgeOS WordPress Plugin
CVE-2022-2958 · HIGH Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections
Learn more about our Wordpress Pen Testing.