← Back to CVE List

CVE-2022-2958

Published: 2022-09-19T14:15Z
Last Modified: 2024-11-21T07:01Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections > MITRE Terms of Use apply – see LICENSE‑MITRE.txt