SQL Injection Vulnerability in BadgeOS WordPress Plugin

SQL Injection Vulnerability in BadgeOS WordPress Plugin

CVE-2022-2958 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections

Learn more about our Wordpress Pen Testing.