CVE-2022-3494 describes a critical SQL injection vulnerability affecting the Complianz WordPress plugin prior to version 6.3.4 and Complianz Premium prior to version 6.3.6. This flaw allows authenticated users with a translator role to inject arbitrary SQL commands via unsanitized translation files, potentially through plugins like Loco Translate or WPML. With a CVSS score of 8.8 (High), the vulnerability presents a low-complexity attack vector that can lead to high impact on confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, the potential for severe data compromise necessitates prompt patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.3.4CPE matchmatch criteria | cpe:2.3:a:really-simple-plugins:complianz:*:*:*:*:-:wordpress:*:* | ||
< 6.3.6CPE matchmatch criteria | cpe:2.3:a:really-simple-plugins:complianz:*:*:*:*:premium:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.