Showing 1 vulnerability on this page for speakout\!_email_petitions

Signals CISA KEV Ransomware Nuclei
speakout\!_email_petitions_project vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

SpeakOut! Email Petitions < 2.14.15.1 - Unauthenticated SQLi

The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via the dk_speakout_sendmail AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CWE-89Mar 28, 20221 related artifact
CVSS9.8v3.1EPSS8.79%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX