CVE-2022-2840 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 12.9% (pctl 96)
Patch early
A public exploit exists.
Description
The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 12.86% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2022-09-19 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| zephyr-one | zephyr project manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Wordpress Plugin Zephyr Project Manager 3.2.42 - Multiple SQLi | 2022-10-06 |
References
- http://packetstormsecurity.com/files/168652/WordPress-Zephyr-Project-Manager-3.2.42-SQL-Injection.html
- https://wpscan.com/vulnerability/13d8be88-c3b7-4d6e-9792-c98b801ba53c
- http://packetstormsecurity.com/files/168652/WordPress-Zephyr-Project-Manager-3.2.42-SQL-Injection.html
- https://wpscan.com/vulnerability/13d8be88-c3b7-4d6e-9792-c98b801ba53c
→ the Explorer · watch your stack · NVD