High severity8.8NVD Advisory· Published Nov 28, 2022· Updated Jun 17, 2026
CVE-2022-3768
CVE-2022-3768
Description
The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:wpsmartcontracts:wpsmartcontracts:*:*:*:*:*:wordpress:*:*Range: <1.3.12
- WordPress/WPSmartContractsdescription
- Range: <1.3.12
Patches
Vulnerability mechanics
References
2- bulletin.iese.de/post/wp-smart-contracts_1-3-11/nvdExploitThird Party Advisory
- wpscan.com/vulnerability/1d8bf5bb-5a17-49b7-a5ba-5f2866e1f8a3nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.