Vulnerability Description
The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscriber
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Icegram | Email Subscribers \& Newsletters | < 5.5.1 |
References
- https://wpscan.com/vulnerability/78054d08-0227-426c-903d-d146e0919028Third Party Advisory
- https://wpscan.com/vulnerability/78054d08-0227-426c-903d-d146e0919028Third Party Advisory
FAQ
What is CVE-2022-3981?
CVE-2022-3981 is a vulnerability with a CVSS score of 8.8 (HIGH). The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated user...
How severe is CVE-2022-3981?
CVE-2022-3981 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-3981?
Check the references section above for vendor advisories and patch information. Affected products include: Icegram Email Subscribers \& Newsletters.