CVE-2022-3925

The buddybadges WordPress plugin through 1.0.0 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users
Configurations

Configuration 1 (hide)

cpe:2.3:a:buddybadges_project:buddybadges:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 07:20

Type Values Removed Values Added
Summary
  • (es) El complemento Buddybadges de WordPress hasta la versión 1.0.0 no sanitiza ni escapa un parámetro antes de usarlo en una declaración SQL, lo que genera una inyección de SQL explotable por usuarios con altos privilegios.
References () https://bulletin.iese.de/post/buddybadges_1-0-0/ - Broken Link () https://bulletin.iese.de/post/buddybadges_1-0-0/ - Broken Link
References () https://wpscan.com/vulnerability/178499a3-97d1-4ab2-abbe-4a9d2ebc85da - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/178499a3-97d1-4ab2-abbe-4a9d2ebc85da - Exploit, Third Party Advisory

Information

Published : 2022-12-12 18:15

Updated : 2025-04-22 15:16


NVD link : CVE-2022-3925

Mitre link : CVE-2022-3925

CVE.ORG link : CVE-2022-3925


JSON object : View

Products Affected

buddybadges_project

  • buddybadges
CWE

No CWE.