VYPR

WPSmartContracts

by Lisandro Martinez

CVEs (2)

  • CVE-2025-31565CriApr 11, 2025
    risk 0.60cvss 9.3epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisandro Martinez WPSmartContracts wp-smart-contracts allows Blind SQL Injection.This issue affects WPSmartContracts: from n/a through <= 2.0.12.

  • CVE-2022-3768Nov 28, 2022
    risk 0.05cvss epss 0.04

    The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author