S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-1013 Scanner

Detects 'SQL Injection (SQLi)' vulnerability in Personal Dictionary Plugin for WordPress affects v. before 1.3.4.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-1013
9.8
CVSS

The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Personal Dictionary
AFFECTED< 1.3.4SAFE ✓≥ 1.3.4
Updated Aug 22, 2026View on NVD →
Detail

The Personal Dictionary Plugin for WordPress is a tool which allows users to create their own personalized dictionary on their WordPress website. This dictionary can come in handy when dealing with specific vocabulary related to their industry or niche. It is a highly popular plugin among writers, bloggers, and professionals. 

CVE-2022-1013 is a severe vulnerability that has been detected in the Personal Dictionary Plugin for WordPress before 1.3.4. The issue takes place because the plugin fails to properly sanitize user supplied POST data before it is interpolated in an SQL statement and executed, leading to a blind SQL injection vulnerability. This vulnerability could potentially allow attackers to execute malicious code on the website, compromise the security of the website, and access sensitive data that entails the personal and financial information of the users.

When the CVE-2022-1013 vulnerability is exploited, it can lead to an array of issues. For instance, it can result in unauthorized access, data breaches, account takeover, and many others. It could also cause significant damages in terms of finances, privacy and website reputation. The malicious code could remain virtually undetected, and the consequences may be disastrous for businesses that rely heavily on their website for their operations.

In conclusion, it is essential for WordPress users to ensure that their plugins are updated regularly to avoid any security risks. By incorporating security measures such as installing web application firewalls, taking regular backups and using pro features of s4e.io, users can effectively mitigate the risks related to the CVE-2022-1013 vulnerability and ensure that their digital assets are safe and secure.

 

REFERENCES

Solution Advice

To protect against the CVE-2022-1013 vulnerability, there are several precautions users must take, as follows:

  • Update to the latest version of the Personal Dictionary Plugin for WordPress (1.3.4) that addresses the SQL injection vulnerability.
  • Disable the Personal Dictionary Plugin for WordPress until the security issue is resolved.
  • Install an effective web application firewall to monitor potential attacks and block unauthorized access to the website.
  • Backup data regularly in case of an intrusion or data loss.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.