← Back to browse · API

CVE-2022-4117

Severity
CRITICAL
CVSS
9.8
EPSS
0.04955
Risk score
40.93
CISA KEV
No
PoC
No
Published
2022-12-26
Modified
2025-04-14
First seen
2026-08-07
Aliases
EUVD-2022-51484, GHSA-9H74-MX6M-3V5R
Products
Unknown:IWS 0 ≤1.0
Sources
euvd EUVD-2022-51484

Description

The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection.

References