Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Wp_user_merger
(Wp_user_merger_project)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 3 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2022-11-28 | CVE-2022-3849 | The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin | Wp_user_merger | 8.8 | ||
2022-11-28 | CVE-2022-3848 | The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin | Wp_user_merger | 8.8 | ||
2022-11-28 | CVE-2022-3865 | The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin | Wp_user_merger | 8.8 |