Vulnerabilities > Adenion > High

DATE CVE VULNERABILITY TITLE RISK
2022-10-25 CVE-2022-3246 Unspecified vulnerability in Adenion Blog2Social
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers
network
low complexity
adenion
8.8
2021-03-18 CVE-2021-24137 SQL Injection vulnerability in Adenion Blog2Social
Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Posts feature, allowing authenticated users to inject arbitrary SQL commands.
network
low complexity
adenion CWE-89
8.8