Critical severity9.8NVD Advisory· Published Jan 2, 2023· Updated Jun 17, 2026
CVE-2022-4297
CVE-2022-4297
Description
The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX available to unauthenticated users, leading to an unauthenticated SQL injection
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- WordPress/WP AutoComplete Searchdescription
- cpe:2.3:a:netflixtech:wp_autocomplete_search:*:*:*:*:*:wordpress:*:*Range: <=1.0.4
- Range: <=1.0.4
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.