WordPress Coming Soon Plugin <= 1.5.9 is vulnerable to SQL Injection
CVE-2022-46849
9.8CRITICAL
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 6 November 2023
Summary
An SQL Injection vulnerability has been identified in the Coming Soon Page – Responsive Coming Soon & Maintenance Mode plugin by Weblizar. This flaw arises from the improper neutralization of special elements within SQL commands, allowing attackers to manipulate database queries. Successful exploitation can compromise the integrity and availability of the database, posing significant risks to users' sensitive data. The affected versions range from n/a up to and including 1.5.9, highlighting the importance of immediate updates and security measures for those using this plugin.
Affected Version(s)
Coming Soon Page – Responsive Coming Soon & Maintenance Mode <= 1.5.9
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Le Ngoc Anh (Patchstack Alliance)