CVE-2022-3254
9.8
CRITICAL · CVSS 3.1 · EPSS 5.6% (pctl 93)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 5.57% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-10-31 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| strategy11 | awp classifieds |
References
→ the Explorer · watch your stack · NVD