packetstormsecurity.com
http://packetstormsecurity.com/files/173293/WordPress-WP-AutoComplete-Search-1.0.4-SQL-Injection.html CVE-2022-4297
CRITICAL
WP AutoComplete Search <= 1.0.4 - Unauthenticated SQLi
Record summary
CVE-2022-4297 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX available to unauthenticated users, leading to an unauthenticated SQL injection
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 11, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WP AutoComplete SearchDefault status: affected | CVE List | Through 1.0.4 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWP AutoComplete 1.0.4 - Unauthenticated SQLiExploitDB exploitby matitaniumNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-4297 wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/e2dcc76c-65ac-4cd6-a5c9-6d813b5ac26d