OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2022-4997

HIGH · CVSS 8.6 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The jet-form-builder-stripe-gateway plugin for WordPress prior to version 1.1.0 is vulnerable due to inadequate sanitization and escaping of payment tokens in SQL statements. This flaw allows unauthenticated users to execute SQL injection attacks, potentially leading to the extraction of sensitive data such as password hashes from the database. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of data breaches.

CVE
CVE-2022-4997
Severity
HIGH
CVSS
8.6
EPSS
0.27%
WordPress

Original NVD Description

The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes.