CVE-2022-4383

CVE-2022-4383: CBX Petition for WordPress <= 1.0.3 - Unauthenticated SQLi

Vendor Unknown
Product CBX Petition for WordPress
Published January 23, 2023
Last update April 2, 2025

CVSS base score

What the vulnerability does

01Description

The CBX Petition for WordPress plugin through 1.0.3 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

Key dates

02Disclosure timeline

January 23, 2023 CVE published
April 2, 2025 Record updated