Vulnerabilities > Highfivery > Zero Spam > 4.9.10
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-03-14 | CVE-2022-0254 | Unspecified vulnerability in Highfivery Zero-Spam The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection | 9.8 |