← Back to browse · API

CVE-2022-4447

Severity
CRITICAL
CVSS
9.8
EPSS
0.04756
Risk score
40.86
CISA KEV
No
PoC
No
Published
2023-01-16
Modified
2025-04-08
First seen
2026-08-07
Aliases
EUVD-2022-51792, GHSA-XJG5-J24F-8P55
Products
Unknown:Fontsy 0 ≤1.8.6
Sources
euvd EUVD-2022-51792

Description

The Fontsy WordPress plugin through 1.8.6 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

References