CVE-2022-1692 is a critical SQL injection vulnerability impacting the CP Image Store with Slideshow WordPress plugin versions before 1.0.68. This flaw, rated 9.8 CVSS Critical, allows unauthenticated attackers to remotely execute SQL commands by manipulating the 'ordering_by' query parameter, potentially leading to a complete compromise of data confidentiality, integrity, and availability. Although not in CISA's KEV catalog, it is on an active hot list, and community discussions confirm the existence of exploit code, including a Nuclei template, indicating a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.68CPE matchmatch criteria | cpe:2.3:a:dwbooster:cp_image_store_with_slideshow:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.