CVE-2022-3142 EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 14.7% (pctl 97)
Patch early
A public exploit exists.
Description
The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be executed by anyone who is permitted to view the forms statistics chart, by default administrators, however can be configured otherwise via the plugin settings.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 14.65% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2022-09-19 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| basixonline | nex-forms |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi | 2023-03-25 |
References
- http://packetstormsecurity.com/files/171477/WordPress-NEX-Forms-SQL-Injection.html
- https://medium.com/%40elias.hohl/authenticated-sql-injection-vulnerability-in-nex-forms-wordpress-plugin-35b8558dd0f5
- https://wpscan.com/vulnerability/8acc0fc6-efe6-4662-b9ac-6342a7823328
- http://packetstormsecurity.com/files/171477/WordPress-NEX-Forms-SQL-Injection.html
- https://medium.com/%40elias.hohl/authenticated-sql-injection-vulnerability-in-nex-forms-wordpress-plugin-35b8558dd0f5
- https://wpscan.com/vulnerability/8acc0fc6-efe6-4662-b9ac-6342a7823328
→ the Explorer · watch your stack · NVD