CVE-2022-0786 Information

Description

The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route leading to SQL Injections exploitable by unauthenticated users

Reference

https://wpscan.com/vulnerability/53f493e9-273b-4349-8a59-f2207e8f8f30

Share on: