S4E just found a medium-severity finding from vulnerable javascript library scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2022-0769

9.8
CVSS
Description

The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users), leading to an SQL Injection.

Attack Vector
-
Privileges Req.
-
User Interaction
-
users ultra membership, users community and member profiles with paypal integration plugin
Updated Sep 22, 2026View on NVD →
S4E scanner

CVE history: users ultra membership, users community and member profiles with paypal integration plugin

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →