iws-geo-form-fields_project Vulnerabilities and Affected Products
Vulnerabilities associated with iws-geo-form-fields.
Products
Clear product- iws-geo-form-fields1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-4117CRITICAL | IWS - Geo Form Fields <= 1.0 - Unauthenticated SQLiThe IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection. | CVSS9.8v3.1 | EPSS4.96% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |