CVE-2022-0769

CVE-2022-0769: Users Ultra <= 3.1.0 - Unauthenticated SQL Injection

Vendor Unknown
Product Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin
Weakness CWE-89 · SQLi
Published April 25, 2022
Last update August 2, 2024

CVSS base score

What the vulnerability does

01Description

The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users), leading to an SQL Injection.

Key dates

02Disclosure timeline

April 25, 2022 CVE published
August 2, 2024 Record updated