CVE-2022-21661

HIGH EXPLOITED NUCLEI LAB

Wordpress < 3.7.37 - SQL Injection

Title source: rule

Description

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this vulnerability.

Exploits (15)

exploitdb WORKING POC
by Aryan Chehreghani · textwebappsphp
https://www.exploit-db.com/exploits/50663
nomisec SCANNER 28 stars
by z92g · infoleak
https://github.com/z92g/CVE-2022-21661
nomisec WORKING POC 17 stars
by purple-WL · infoleak
https://github.com/purple-WL/wordpress-CVE-2022-21661
nomisec WORKING POC 14 stars
by 0x4E0x650x6F · infoleak
https://github.com/0x4E0x650x6F/Wordpress-cve-CVE-2022-21661
nomisec WORKING POC 7 stars
by guestzz · poc
https://github.com/guestzz/CVE-2022-21661
nomisec WORKING POC 6 stars
by WellingtonEspindula · remote
https://github.com/WellingtonEspindula/SSI-CVE-2022-21661
nomisec WORKING POC 6 stars
by sealldeveloper · remote
https://github.com/sealldeveloper/CVE-2022-21661-PoC
nomisec WORKING POC 2 stars
by daniel616 · remote
https://github.com/daniel616/CVE-2022-21661-Demo
nomisec STUB
by 7rootsec · poc
https://github.com/7rootsec/CVE-2022-21661-Technical-Analysis
nomisec WORKING POC
by Fauzan-Aldi · infoleak
https://github.com/Fauzan-Aldi/CVE-2022-21661
nomisec WORKING POC
by w0r1i0g1ht · infoleak
https://github.com/w0r1i0g1ht/CVE-2022-21661
nomisec WRITEUP
by CharonDefalt · infoleak
https://github.com/CharonDefalt/WordPress--CVE-2022-21661
nomisec SCANNER
by p4ncontomat3 · remote-auth
https://github.com/p4ncontomat3/CVE-2022-21661
nomisec WRITEUP
by safe3s · poc
https://github.com/safe3s/CVE-2022-21661

Nuclei Templates (1)

WordPress <5.8.3 - SQL Injection
HIGHVERIFIEDby Marcio Mendes
Shodan: cpe:"cpe:2.3:a:wordpress:wordpress" || http.component:"wordpress"

Scores

CVSS v3 8.0
EPSS 0.9053
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull wordpress:5.8.1
docker pull wordpress:cli
docker pull wordpress:5.8.2
+10 more repos

Details

VulnCheck KEV 2023-12-23
CWE
CWE-89
Status published
Products (6)
debian/debian_linux 9.0
debian/debian_linux 10.0
debian/debian_linux 11.0
fedoraproject/fedora 34
fedoraproject/fedora 35
wordpress/wordpress 3.7 - 3.7.37
Published Jan 06, 2022
Tracked Since Feb 18, 2026