The WP User Merger Project maintains a specialized WordPress plugin focused on user account consolidation, presenting a narrowly scoped but directly accessible attack surface in WordPress environments. The observed vulnerability profile centers on SQL injection flaws affecting the core plugin, a weakness class that carries particular risk in data-manipulation contexts where user records are aggregated. Current exploitation activity, severity distribution, and exposure breadth are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wp User Merger Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3865HIGH The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by use | Nov 28, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-3849HIGH The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by use | Nov 28, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-3848HIGH The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by use | Nov 28, 2022 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wp User Merger Project.
Media articles that mention a CVE ID that affects a product developed by Wp User Merger Project — matched by CVE ID, not by vendor name.