rootpwn

high · CVSS v3 8.6 · EPSS 0.00235

CVE-2022-4997

The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before us…

Description

The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes.

Scores

Severity
high
CVSS v2
7.8
CVSS v3
8.6
CVSS v4
EPSS
0.00235

← All CVEs