cleantalk
Vulnerabilities and Security Researches

WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds, CVE-2022-3254

CVE, Research URL

CVE-2022-3254

Published on
Oct 31, 2022
Research Description
The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection
Affected versions
max 2.0.
Status
vulnerable