CVE-2022-21661 is a high-severity SQL injection vulnerability affecting WordPress versions up to 5.8.2, stemming from improper sanitization in WP_Query that can be exploited through plugins or themes. This vulnerability has a CVSS score of 7.5 (High) and allows for unauthenticated remote attackers to achieve high confidentiality impact. While not currently on the KEV catalog, public exploit code exists, including a Metasploit module and Nuclei templates, and it has garnered significant community discussion and media coverage, indicating a high potential for exploitation. WordPress has released patches for all affected versions, back to 3.7.37, and strongly recommends enabling auto-updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.7, < 3.7.37CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | ||
>= 3.8, < 3.8.37CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | ||
>= 3.9, < 3.9.35CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | ||
>= 4.0, < 4.0.34CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | ||
>= 4.1, < 4.1.34CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.