FL3R FeelBox <= 8.1 - Unauthenticated SQLi
CVE-2022-4445
Key Information:
- Vendor
Wordpress
- Status
- Vendor
- CVE Published:
- 13 February 2023
Badges
What is CVE-2022-4445?
The FL3R FeelBox WordPress plugin prior to version 8.2 contains a SQL injection vulnerability due to inadequate sanitization and escaping of a parameter in an AJAX action accessible to unauthenticated users. This flaw can allow attackers to manipulate SQL queries and gain unauthorized access to sensitive data, posing significant security risks to WordPress sites utilizing this plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FL3R FeelBox 0 <= 8.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved