High severity7.2NVD Advisory· Published Apr 4, 2022· Updated Jun 17, 2026
CVE-2022-0887
CVE-2022-0887
Description
The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:cybernetikz:easy_social_icons:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:cybernetikz:easy_social_icons:*:*:*:*:*:wordpress:*:*range: <3.1.4
- (no CPE)range: 3.1.4
- Range: <3.1.4
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/a6c1676d-9dcb-45f6-833a-9545bccd0ad6nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.