Products

Showing 1 vulnerability on this page

Signals CISA KEV Ransomware Nuclei
usersultra vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Users Ultra <= 3.1.0 - Unauthenticated SQL Injection

The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users), leading to an SQL Injection.

CWE-89Apr 25, 20221 related artifact
CVSS9.8v3.1EPSS8.54%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX