CVE-2022-0949
9.8
CRITICAL · CVSS 3.1 · EPSS 7.7% (pctl 94)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX action, available to unauthenticated users, leading to a SQL injection
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 7.67% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-04-11 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| stopbadbots | block and stop bad bots |
References
→ the Explorer · watch your stack · NVD