S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-21661 Scanner

CVE-2022-21661 scanner - SQL Injection vulnerability in WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-21661
7.5
CVSShigh
Exploitable remotely over the internet · requires high privileges.

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this vulnerability.

Attack Vector
Network
Privileges Req.
High
User Interaction
None
Affected
wordpress-developby WordPress
< 5.8.3
Updated Aug 22, 2026View on NVD →
Detail

WordPress is a leading content management system (CMS) used to create and manage websites. It's known for its ease of use, flexibility, and extensibility through themes and plugins. WordPress powers a significant portion of the internet, from personal blogs to complex websites of major corporations. It provides a platform for users to publish content, engage with their audience, and customize their site's appearance and functionality. WordPress is maintained by a community of developers and contributors who regularly update the core software to enhance features, security, and performance.

The flaw specifically impacts the handling of certain parameters within WP_Query, where unsanitized inputs can be manipulated to construct malicious SQL queries. This vulnerability requires no authentication, making it possible for an unauthenticated attacker to exploit it by crafting a request that includes a malicious SQL query. The attack can be carried out through plugins or themes that incorrectly handle user input and pass it to WP_Query, demonstrating the importance of proper input validation and sanitization in all components of a WordPress site.

Successful exploitation of this vulnerability can allow attackers to perform SQL injection attacks, leading to unauthorized access to the site's database. This could result in the leakage of sensitive information, such as user credentials, personal data, or proprietary content. Moreover, attackers could potentially manipulate or delete data, causing disruption to the website's operation and compromising the integrity of the site.

By utilizing the S4E platform, users gain access to sophisticated scanning tools capable of detecting vulnerabilities like CVE-2022-21661 in WordPress, as well as other security weaknesses across their digital assets. Our platform offers comprehensive vulnerability assessments, real-time monitoring, and expert guidance to address security issues effectively. Joining S4E enables you to enhance your site's security posture, protect against cyber threats, and ensure the safety and privacy of your users.

 

References

Solution Advice
  1. Update WordPress to version 5.8.3 or later, which contains patches for this vulnerability. If using an older version, ensure that you apply the security release that goes back to version 3.7.37.
  2. Regularly update all themes and plugins to their latest versions to close security gaps.
  3. Enable auto-updates for WordPress, themes, and plugins to ensure timely application of security patches.
  4. Use security plugins that provide additional protections against SQL injection and other vulnerabilities.
  5. Review custom code, especially where user inputs are handled, to ensure proper sanitization and validation practices are in place.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.