Vulnerability Details CVE-2022-2460
The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities exploitable by unauthenticated users
Exploit prediction scoring system (EPSS) score
EPSS Score 0.041
EPSS Ranking 88.1%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-2460
-
cpe:2.3:a:digital_product_labs:wpdating:7.1.9