CVE-2022-0434 is a critical SQL injection vulnerability affecting the Page View Count WordPress plugin versions prior to 2.4.15. It allows unauthenticated attackers to execute arbitrary SQL commands due to improper sanitization of the post_ids parameter in a REST endpoint. With a CVSS score of 9.8 (Critical), this vulnerability has a high impact on confidentiality, integrity, and availability, requiring no user interaction or privileges to exploit. While there is no evidence of active exploitation or KEV listing, Nuclei templates exist, and its high EPSS score suggests a significant likelihood of future exploitation. Community discussion and media coverage for this CVE are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.15CPE matchmatch criteria | cpe:2.3:a:a3rev:page_view_count:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.