peter bassill · operator
$ cve CVE-2022-2754 JSON

CVE-2022-2754

9.8
CRITICAL · CVSS 3.1 · EPSS 38.3% (pctl 99)

Patch early

EPSS 38.3% — above the 10% action threshold.

Description

The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS38.33% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploitnone known
Published2022-09-19
Last modified2026-06-17

Affected (1)

VendorProduct
ketchup restaurant reservations projectketchup restaurant reservations

References

→ the Explorer  ·  watch your stack  ·  NVD