Vulnerabilities (CVE)

Filtered by vendor Nirweb Subscribe
Filtered by product Nirweb Support
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-0781 1 Nirweb 1 Nirweb Support 2024-11-21 7.5 HIGH 9.8 CRITICAL
The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection