The Joy Of Text Lite WordPress plugin before 2.3.1 does not properly sanitise and escape some parameters before using them in SQL statements accessible to unauthenticated users, leading to unauthenticated SQL injection
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-01-02T21:49:32.669Z

Updated: 2024-08-03T01:27:54.387Z

Reserved: 2022-11-21T12:56:38.644Z

Link: CVE-2022-4099

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-01-02T22:15:16.010

Modified: 2024-11-21T07:34:34.890

Link: CVE-2022-4099

cve-icon Redhat

No data.