cleantalk
Vulnerabilities and Security Researches

NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor, CVE-2022-0349

CVE, Research URL

CVE-2022-0349

Published on
Mar 07, 2022
Research Description
The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection
Affected versions
max 1.8.3.
Status
vulnerable