S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0693 Scanner

CVE-2022-0693 scanner - SQL Injection (SQLi) vulnerability in Master Elements plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0693
9.8
CVSS

The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL Injection

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Master Elements
8.0
Updated Aug 22, 2026View on NVD →
Detail

The Master Elements WordPress plugin is a popular tool used for creating interactive and dynamic web pages on WordPress-based websites. It offers numerous features such as custom post types, elements library, and layout design tools. The plugin allows users to easily design and manage the appearance of their webpage, making it one of the most popular website designing plugins available for WordPress users.

However, the plugin has recently been found to have a serious vulnerability that has been assigned CVE-2022-0693. This vulnerability occurs due to a lack of sanitization of the meta_ids parameter of the remove_post_meta_condition AJAX action. The plugin allows both authenticated and unauthenticated users to manipulate the parameter, which in turn can lead to an SQL Injection attack.

Exploitation of this vulnerability can lead to a range of serious consequences such as unauthorized access to sensitive data, website defacement, and malicious code injection. The SQL Injection attack enabled by the vulnerability can be used to bypass security systems, steal sensitive information, and even take control of the website completely. The potential damages are limitless and can be devastating for website owners and users.

At s4e.io, we offer pro features that can aid individuals in identifying and fixing security vulnerabilities on their digital assets. Our platform provides comprehensive vulnerability management tools that allow users to scan, identify, and fix vulnerabilities on their websites. With our services, individuals can be assured of the security of their digital assets and have peace of mind knowing that their websites are protected from vulnerabilities like CVE-2022-0693.

 

REFERENCES

Solution Advice

To prevent exploitation of this vulnerability, it is important for website owners to take adequate precautions. Here are some recommended measures that can be taken:

  • Update the Master Elements WordPress plugin to the latest version that has fixed the vulnerability.
  • Restrict access to the remove_post_meta_condition AJAX action to authenticated users only.
  • Implement security measures like web application firewalls and MySQL injection prevention plugins to safeguard against similar vulnerabilities.
  • Conduct regular security audits to identify and remediate vulnerabilities on the website.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.