High severity7.2NVD Advisory· Published Jan 2, 2023· Updated Jun 17, 2026
CVE-2022-4356
CVE-2022-4356
Description
The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:letsrecover_project:letsrecover:*:*:*:*:*:wordpress:*:*Range: <=1.1.0
- WordPress/LetsRecoverdescription
- Range: <1.2.0
Patches
Vulnerability mechanics
References
3- bulletin.iese.de/post/letsrecover-woocommerce-abandoned-cart_1-1-0_3nvdBroken LinkThird Party Advisory
- wpscan.com/vulnerability/27a8d7cb-e179-408e-af13-8722ab41947bnvdThird Party Advisory
- wpscan.com/vulnerability/27a8d7cb-e179-408e-af13-8722ab41947b/nvd
News mentions
0No linked articles in our index yet.