peter bassill · operator
$ cve CVE-2022-3142 JSON

CVE-2022-3142 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 14.7% (pctl 97)

Patch early

A public exploit exists.

Description

The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be executed by anyone who is permitted to view the forms statistics chart, by default administrators, however can be configured otherwise via the plugin settings.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS14.65% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2022-09-19
Last modified2026-06-17

Affected (1)

VendorProduct
basixonlinenex-forms

Public exploits

SourceTitleDate
exploit-dbNEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi2023-03-25

References

→ the Explorer  ·  watch your stack  ·  NVD