CVE-2022-4546 Information

Description

The Mapwiz WordPress plugin through 1.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement leading to a SQL injection exploitable by high privilege users such as admin.

Reference

https://wpscan.com/vulnerability/009578b9-016d-49c2-9577-49756c35e1e8 https://bulletin.iese.de/post/mapwiz_1-0-1/

Share on: