WordPress Coming Soon Plugin <= 1.5.9 is vulnerable to SQL Injection
CVE-2022-46849

9.8CRITICAL

Key Information:

Vendor
WordPress
Vendor
CVE Published:
6 November 2023

Summary

An SQL Injection vulnerability has been identified in the Coming Soon Page – Responsive Coming Soon & Maintenance Mode plugin by Weblizar. This flaw arises from the improper neutralization of special elements within SQL commands, allowing attackers to manipulate database queries. Successful exploitation can compromise the integrity and availability of the database, posing significant risks to users' sensitive data. The affected versions range from n/a up to and including 1.5.9, highlighting the importance of immediate updates and security measures for those using this plugin.

Affected Version(s)

Coming Soon Page – Responsive Coming Soon & Maintenance Mode <= 1.5.9

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Le Ngoc Anh (Patchstack Alliance)
.