cleantalk
Vulnerabilities and Security Researches

FundEngine – Donation and Crowdfunding Platform, CVE-2022-0788

CVE, Research URL

CVE-2022-0788

Published on
Jun 08, 2022
Research Description
The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a parameter before using it in a SQL statement via one of it's REST route, leading to an SQL injection exploitable by unauthenticated users
Affected versions
Min -, max 1.5.0.
Status
vulnerable