CVE-2022-0773

CRITICAL NUCLEI

Documentor WP <1.5.3 - SQL Injection

Title source: llm

Description

The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users.

Nuclei Templates (1)

Documentor <= 1.5.3 - Unauthenticated SQL Injection
CRITICALVERIFIEDby theamanrawat

Scores

CVSS v3 9.8
EPSS 0.7140
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
documentor_project/documentor < 1.5.3
Published May 02, 2022
Tracked Since Feb 18, 2026