peter bassill · operator
$ cve CVE-2022-21661 JSON

CVE-2022-21661 EXPLOIT

8.0
HIGH · CVSS 3.1 · EPSS 97.8% (pctl 100)

Patch early

A public exploit exists.

Description

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this vulnerability.

Scoring

CVSS8.0 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS97.8% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2022-01-06
Last modified2026-06-17

Affected (3)

VendorProduct
debiandebian linux
fedoraprojectfedora
wordpresswordpress

Public exploits

SourceTitleDate
exploit-dbWordPress Core 5.8.2 - 'WP_Query' SQL Injection2022-01-13

References

→ the Explorer  ·  watch your stack  ·  NVD