AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-4230

HIGH · CVSS 8.8 EPSS 35.68%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-01-23 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-4230
Severity
HIGH
CVSS
8.8
EPSS
35.68%
WordPress

Original NVD Description

The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to access it as well.