QID 730333

Date Published: 2022-01-18

QID 730333: WordPress Prior to 4.1.34 and 5.8.3 SQL Injection Vulnerability

WordPress is software designed for everyone, emphasizing accessibility, performance, security, and ease of use.

CVE-2022-21664: Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed.

Affected Versions:
WordPress versions from 4.1.x prior to 4.1.34
WordPress versions from 5.0.0 prior to 5.8.3

QID Detection Logic:
The QID checks for the version via the meta generator tag.

Successful exploitation of this vulnerability may allow an unauthenticated remote attacker to execute arbitrary SQL queries on the target system.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Customers are advised to upgrade to the fixed versions 5.8.3 to remediate these vulnerabilities:
    For more Information Please visit WordPress site

    CVEs related to QID 730333

    Software Advisories
    Advisory ID Software Component Link
    WordPress 5.8.3 URL Logo wordpress.org/news/2022/01/wordpress-5-8-3-security-release/