HIGH

CVE-2022-21661

CVSS v3

7.5

HIGH

EPSS Score

90.9%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this vulnerability.

Technical details

Published
1/6/2022

Frequently asked questions

What is CVE-2022-21661?

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this vulnerability.

Is CVE-2022-21661 actively exploited?

Active exploitation of CVE-2022-21661 has not been confirmed. The EPSS score is 90.9%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-21661?

CVE-2022-21661 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2022-21661 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.