Zero Spam < 5.2.11 - Admin+ SQL Injection
CVE-2022-0254
9.8CRITICAL
What is CVE-2022-0254?
The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection
Affected Version(s)
WordPress Zero Spam 5.2.11