Vulnerability Details CVE-2022-0787
The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections
Exploit prediction scoring system (EPSS) score
EPSS Score 0.444
EPSS Ranking 97.5%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2022-0787
-
cpe:2.3:a:limit_login_attempts_project:limit_login_attempts:1.0
-
cpe:2.3:a:limit_login_attempts_project:limit_login_attempts:1.1
-
cpe:2.3:a:limit_login_attempts_project:limit_login_attempts:1.2
-
cpe:2.3:a:limit_login_attempts_project:limit_login_attempts:1.3
-
cpe:2.3:a:limit_login_attempts_project:limit_login_attempts:1.3.1
-
cpe:2.3:a:limit_login_attempts_project:limit_login_attempts:1.3.2
-
cpe:2.3:a:limit_login_attempts_project:limit_login_attempts:1.4
-
cpe:2.3:a:limit_login_attempts_project:limit_login_attempts:1.4.1
-
cpe:2.3:a:limit_login_attempts_project:limit_login_attempts:1.5
-
cpe:2.3:a:limit_login_attempts_project:limit_login_attempts:1.5.1
-
cpe:2.3:a:limit_login_attempts_project:limit_login_attempts:1.5.2
-
cpe:2.3:a:limit_login_attempts_project:limit_login_attempts:1.6.0
-
cpe:2.3:a:limit_login_attempts_project:limit_login_attempts:1.6.1
-
cpe:2.3:a:limit_login_attempts_project:limit_login_attempts:1.6.2
-
cpe:2.3:a:limit_login_attempts_project:limit_login_attempts:1.7.0
-
cpe:2.3:a:limit_login_attempts_project:limit_login_attempts:1.7.1
-
cpe:2.3:a:limit_login_attempts_project:limit_login_attempts:1.7.2