{"id":"CVE-2022-0254","aliases":[],"url":"https://o3.security/vulnerability/CVE-2022-0254","summary":"SQL Injection in WordPress Zero Spam WordPress plugin","details":"The WordPress Zero Spam WordPress plugin before 5.2.13 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection","published":"2022-03-15T00:00:57Z","modified":"2023-11-08T04:07:30.702484Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01997,"percentile":0.78719,"asOf":"2026-07-31"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"bmarshall511/wordpress_zero_spam","fixedVersion":"5.2.13"}],"fix":{"url":"https://github.com/Highfivery/zero-spam-for-wordpress/commit/49723f696f1e2f2a76ac89375910bb036a4895f3","label":"Highfivery/zero-spam-for-wordpress@49723f6"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0254"},{"type":"WEB","url":"https://github.com/Highfivery/zero-spam-for-wordpress/commit/49723f696f1e2f2a76ac89375910bb036a4895f3"},{"type":"PACKAGE","url":"https://github.com/Highfivery/zero-spam-for-wordpress"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/changeset/2660225"},{"type":"WEB","url":"https://plugins.trac.wordpress.org/changeset/2680906"},{"type":"WEB","url":"https://wpscan.com/vulnerability/ae54681f-7b89-408c-b0ee-ba4a520db997"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:07:30.702484Z"}}