← Back to browse · API

CVE-2022-4049

Severity
CRITICAL
CVSS
9.8
EPSS
0.04756
Risk score
40.86
CISA KEV
No
PoC
No
Published
2023-01-02
Modified
2025-04-10
First seen
2026-08-07
Aliases
EUVD-2022-51426, GHSA-VQ28-QP88-5GWG
Products
Unknown:WP User 0 ≤7.0
Sources
euvd EUVD-2022-51426

Description

The WP User WordPress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

References