CVE-2022-1950 Information

Description

The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users leading to an unauthenticated SQL injection

Reference

https://wpscan.com/vulnerability/4352283f-dd43-4827-b417-0c55d0f4637d

Share on: