Vulnerability Description
The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Secondlinethemes | Podcast Importer Secondline | < 1.3.8 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset/2696254PatchThird Party Advisory
- https://wpscan.com/vulnerability/163069cd-98a8-4cfb-8b58-a6727a7d5c48ExploitPatchThird Party Advisory
- https://plugins.trac.wordpress.org/changeset/2696254PatchThird Party Advisory
- https://wpscan.com/vulnerability/163069cd-98a8-4cfb-8b58-a6727a7d5c48ExploitPatchThird Party Advisory
FAQ
What is CVE-2022-1023?
CVE-2022-1023 is a vulnerability with a CVSS score of 7.2 (HIGH). The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious ...
How severe is CVE-2022-1023?
CVE-2022-1023 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1023?
Check the references section above for vendor advisories and patch information. Affected products include: Secondlinethemes Podcast Importer Secondline.