Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-0769

The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users), leading to an SQL Injection.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.77
EPSS Ranking 98.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2022-0769


Contact Us

Shodan ® - All rights reserved