Vulnerabilities > CVE-2022-0657 - Unspecified vulnerability in 5 Stars Rating Funnel Project 5 Stars Rating Funnel

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
5-stars-rating-funnel-project
critical

Summary

The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue. There is an attempt to sanitise the input, using sanitize_text_field(), however such function is not intended to prevent SQL injections.

Vulnerable Configurations

Part Description Count
Application
5_Stars_Rating_Funnel_Project
1